Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   TR/Agent.1042480 und setupdralex.exe (Backdoor.Bot) (https://www.trojaner-board.de/107687-tr-agent-1042480-setupdralex-exe-backdoor-bot.html)

dieba 06.01.2012 18:14

TR/Agent.1042480 und setupdralex.exe (Backdoor.Bot)
 
Hallo,

es geht um den Laptop meiner Frau, ein Targa Traveller 1720 ML42 mit Vista Home Basic. In den letzten Monaten wurde das Arbeiten manchmal sehr mühsam, da zeitweise permanenter Plattenzugriff das Arbeiten blockierte. Ebenfalls waren Bootzeit und die Zeit, bis nach dem Booten eine vernünftige Eingabe möglich war, sehr verlängert. Am 1. Januar blieb der Rechner beim Herunterfahren hängen, nach ca 1/2 Stunde Wartezeit schaltete ich ihn dann aus. Anschließend ließ er sich nicht mehr booten, auch die Recovery-CD blieb beim booten an der gleichen Stelle hängen. Über F10 (ich wollte eigentlich in Bios) bekam ich eine Option gepromptet (weiss leider nicht mehr den Namen), über die der Rechner Gottseidank wieder bootete. Ich habe danach aufgeräumt und eine Sicherung erstellt. Die Deaktivierung von Superfetch und einiger autorun starts (u.a. Spybot S&D) brachte bzgl der Plattenzugriffe einige Erleichterung. Beim Aufräumen stiess ich allerdings auf zwei Hinweise:

1. Avira zeigte mir unter Quarantäne an: Datei C:\Program Files\Nero\Nero 7\Nero Vision\NeroVision.exe ist das Trojanische Pferd TR/Agent.1042480 21.07.2011 (leider kein log mehr vorhanden)
ein letzter Avira Vollscan lieferte HKEY_LOCAL_MACHINE\Software\DeterministicNetworks\DNE\Parameters\symboliclinkvalue [HINWEIS] Der Registrierungseintrag ist nicht sichtbar. (logdatei angehängt)

2. Malwarebytes zeigte mir an Infizierte Dateien:
c:\Users\christa\downloads\setupdralex.exe (Backdoor.Bot) -> Quarantined and deleted successfully. (logdatei angehängt)

Nun habe ich Bedenken, dass der Rechner doch kompromittiert sein könnte, und würde mich über Info/Rat freuen.

Ich habe mich durch http://www.trojaner-board.de/69886-a...-beachten.html durchgearbeitet und bin bei 2 Stellen hängen geblieben: defogger lief ohne Probleme durch, aus der Anleitung ging für mich aber nicht eindeutig hervor, ob ich nur im Fehlerfall nicht auf "re-enable" drücken darf, habe das Programm ohne Drücken beendigt. War das ok? Und beim Zippen der Logdateien habe ich erst .7z Archiv (default) erstellt, bis ich dann merkte, dass nur .zip hochgeladen werden darf. Vielleicht dazu noch ein Hinweis in der Anleitung.

Danke im voraus,
dieba

Code:

OTL logfile created on: 06.01.2012 13:56:11 - Run 1
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\christa\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
894,71 Mb Total Physical Memory | 489,17 Mb Available Physical Memory | 54,67% Memory free
3,84 Gb Paging File | 3,10 Gb Available in Paging File | 80,72% Paging File free
Paging file location(s): c:\pagefile.sys 3072 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 101,57 Gb Total Space | 50,42 Gb Free Space | 49,64% Space Free | Partition Type: NTFS
 
Computer Name: FREIZEIT | User Name: christa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.01.06 13:50:59 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\christa\Desktop\OTL.exe
PRC - [2011.07.01 11:03:22 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.04.28 11:54:41 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2010.11.30 18:12:37 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010.01.14 21:10:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.04.11 07:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2008.09.25 13:07:58 | 000,181,624 | ---- | M] (CANON INC.) -- C:\Windows\System32\spool\drivers\w32x86\3\CNAP2RPK.EXE
PRC - [2008.09.22 07:02:08 | 001,119,624 | ---- | M] (CANON INC.) -- C:\Windows\System32\spool\drivers\w32x86\3\CNAB8SWK.EXE
PRC - [2006.12.29 11:11:00 | 004,317,184 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2006.10.31 22:40:16 | 000,077,824 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
PRC - [2006.10.19 14:42:00 | 000,065,536 | ---- | M] (O2Micro International) -- C:\Windows\System32\o2flash.exe
PRC - [2006.03.22 11:07:22 | 000,040,960 | ---- | M] () -- C:\Programme\System Control Manager\edd.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2009.12.21 19:09:26 | 000,016,832 | ---- | M] () -- C:\Programme\Adobe\Reader 9.0\Reader\ViewerPS.dll
MOD - [2007.01.08 12:08:56 | 000,159,744 | ---- | M] () -- C:\Windows\System32\atitmmxx.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011.07.01 11:03:22 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.28 11:54:41 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2008.12.12 03:20:08 | 000,095,896 | ---- | M] (SiSoftware) [Disabled | Stopped] -- C:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP1\RpcAgentSrv.exe -- (SandraAgentSrv)
SRV - [2008.10.23 16:45:14 | 000,307,200 | ---- | M] (T-Systems Enterprise Services GmbH) [On_Demand | Stopped] -- C:\Program Files\DSL-Manager\DslMgrSvc.exe -- (TDslMgrService)
SRV - [2008.01.19 08:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2006.10.31 22:40:16 | 000,077,824 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
SRV - [2006.10.23 13:50:35 | 000,046,640 | R--- | M] (AOL LLC) [Disabled | Stopped] -- C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe -- (AOL ACS)
SRV - [2006.10.19 14:42:00 | 000,065,536 | ---- | M] (O2Micro International) [Auto | Running] -- C:\Windows\System32\o2flash.exe -- (O2Flash)
SRV - [2006.03.22 11:07:22 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\Programme\System Control Manager\edd.exe -- (NishService)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011.07.01 11:03:26 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.07.01 11:03:26 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010.06.17 14:27:02 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.08.07 22:46:56 | 000,023,112 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- C:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP1\WNt500x86\sandra.sys -- (SANDRA)
DRV - [2009.02.13 11:35:01 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Programme\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2007.11.22 11:06:08 | 000,893,440 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athrusb.sys -- (athrusb)
DRV - [2007.11.21 10:21:06 | 000,015,890 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\mdc8021x.sys -- (MDC8021X) AEGIS Protocol (IEEE 802.1x)
DRV - [2007.09.12 17:24:00 | 000,026,816 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DslTestSp5.sys -- (dsltestSp5)
DRV - [2007.08.01 15:49:00 | 000,016,448 | ---- | M] (T-Systems Enterprise Services GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\dslmnlwf.sys -- (DslMNLwf)
DRV - [2007.05.11 15:28:30 | 000,357,376 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\netr61.sys -- (rt61x86)
DRV - [2007.01.19 09:41:06 | 000,077,824 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGR1310_60.sys -- (AGR1310_60)
DRV - [2007.01.08 12:16:50 | 002,313,216 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2006.11.30 16:30:30 | 000,811,440 | ---- | M] (Bison Electronics. Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\BisonCam.sys -- (Cam5603D)
DRV - [2006.11.20 15:14:08 | 000,038,400 | ---- | M] (O2Micro ) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\o2media.sys -- (O2MDRDR)
DRV - [2006.11.17 13:58:32 | 000,031,360 | ---- | M] (O2Micro ) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\o2sd.sys -- (O2SDRDR)
DRV - [2006.11.02 08:41:50 | 000,983,552 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006.11.01 21:18:15 | 000,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - [2006.10.28 00:29:10 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2006.10.05 16:07:46 | 000,073,600 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TosRfhid.sys -- (Tosrfhid)
DRV - [2006.09.21 14:22:42 | 000,113,920 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TosRfbd.sys -- (tosrfbd)
DRV - [2006.07.10 15:17:48 | 000,016,896 | ---- | M] (WideView Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BDA_Loader_220A.sys -- (BDA_Loader_220A)
DRV - [2006.07.03 10:31:26 | 000,009,088 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\MGHwCtrl.sys -- (MGHwCtrl)
DRV - [2005.08.18 18:22:30 | 000,110,080 | ---- | M] (Deterministic Networks, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\dne2000.sys -- (DNE)
DRV - [2005.08.01 16:45:08 | 000,064,896 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2005.05.17 03:51:34 | 000,005,315 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CVirtA.sys -- (CVirtA)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.juelich.de/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.selectedEngine: "Google Deutschland"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.juelich.de/stabue/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.5
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {53A03D43-5363-4669-8190-99061B2DEBA5}:1.4.3
FF - prefs.js..extensions.enabledItems: ietab@ip.cn:1.98.20110322
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.01.04 12:33:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.04.03 18:34:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011.10.13 20:35:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
 
[2010.08.20 11:06:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\christa\AppData\Roaming\mozilla\Extensions
[2010.08.20 11:06:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\christa\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012.01.06 12:38:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\christa\AppData\Roaming\mozilla\Firefox\Profiles\8p6t23gq.default\extensions
[2010.05.24 10:07:42 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\christa\AppData\Roaming\mozilla\Firefox\Profiles\8p6t23gq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.12.14 19:23:23 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\christa\AppData\Roaming\mozilla\Firefox\Profiles\8p6t23gq.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011.11.12 18:02:53 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\christa\AppData\Roaming\mozilla\Firefox\Profiles\8p6t23gq.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011.03.26 20:52:04 | 000,000,000 | ---D | M] (IE Tab Plus) -- C:\Users\christa\AppData\Roaming\mozilla\Firefox\Profiles\8p6t23gq.default\extensions\ietab@ip.cn
[2012.01.06 12:38:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\christa\AppData\Roaming\mozilla\Firefox\Profiles\8p6t23gq.default\extensions\staged
[2012.01.03 17:22:08 | 000,002,128 | ---- | M] () -- C:\Users\christa\AppData\Roaming\Mozilla\Firefox\Profiles\8p6t23gq.default\searchplugins\booklooker.xml
[2012.01.03 17:22:08 | 000,005,203 | ---- | M] () -- C:\Users\christa\AppData\Roaming\Mozilla\Firefox\Profiles\8p6t23gq.default\searchplugins\buchticket-autorensuche.xml
[2012.01.03 17:22:09 | 000,002,454 | ---- | M] () -- C:\Users\christa\AppData\Roaming\Mozilla\Firefox\Profiles\8p6t23gq.default\searchplugins\google-deutschland.xml
[2012.01.03 17:22:09 | 000,002,786 | ---- | M] () -- C:\Users\christa\AppData\Roaming\Mozilla\Firefox\Profiles\8p6t23gq.default\searchplugins\google-images.xml
[2012.01.03 17:22:09 | 000,002,007 | ---- | M] () -- C:\Users\christa\AppData\Roaming\Mozilla\Firefox\Profiles\8p6t23gq.default\searchplugins\leo-en-de.xml
[2012.01.04 12:33:43 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
() (No name found) -- C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\EXTENSIONS\{53A03D43-5363-4669-8190-99061B2DEBA5}.XPI
() (No name found) -- C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\EXTENSIONS\{CE6E6E3B-84DD-4CAC-9F63-8D2AE4F30A4B}.XPI
() (No name found) -- C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012.01.04 12:33:39 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012.01.04 12:33:35 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.01.04 12:33:35 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.01.04 12:33:35 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.01.04 12:33:35 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.01.04 12:33:35 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.01.04 12:33:35 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\christa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2011.11.10 11:20:39 | 000,000,000 | -H-D | M]
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Öffnen mit WordPerfect - C:\Programme\WordPerfect Office X3\Programs\WPLauncher.hta ()
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} hxxp://www3.snapfish.de/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0C1F45C5-0DFA-4E69-87DD-49FAC983ED1C}: DhcpNameServer = 172.16.15.254 10.0.0.138 194.109.6.66
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1F988EA9-9DF7-4BEE-B4D9-821228261E1C}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{63875ECE-B993-498D-8FA7-8E83293B6696}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B2965EE1-3C04-423A-A5A1-A3197B0707FA}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\AutorunsDisabled - No CLSID value found
O18 - Protocol\Handler\AutorunsDisabled\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\AutorunsDisabled\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\AutorunsDisabled\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\AutorunsDisabled\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Programme\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\AutorunsDisabled - No CLSID value found
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 16777216
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Macromedia Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: AutorunsDisabled -
ActiveX: ccc-core-static - msiexec /fums {AA696568-50B5-9FAA-60D7-9C333239C3A4} /qb
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^phase-6 Reminder.lnk - C:\Programme\phase-6\phase-6-basic\reminder\reminder.exe - (phase-6)
MsConfig - StartUpReg: Adobe ARM - hkey= - key= -  File not found
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: Malwarebytes' Anti-Malware (reboot) - hkey= - key= - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
MsConfig - StartUpReg: Sidebar - hkey= - key= -  File not found
MsConfig - StartUpReg: Skype - hkey= - key= -  File not found
MsConfig - StartUpReg: SpybotSD TeaTimer - hkey= - key= - C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
MsConfig - StartUpReg: swg - hkey= - key= - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
MsConfig - State: "startup" - 2
MsConfig - State: "services" - 0
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.01.06 13:50:53 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\christa\Desktop\OTL.exe
[2012.01.04 21:10:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012.01.04 21:10:10 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2012.01.04 18:10:51 | 000,000,000 | ---D | C] -- C:\Users\christa\!!Systemänderungen
[2012.01.04 17:29:07 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled
[2012.01.03 20:13:49 | 000,000,000 | ---D | C] -- C:\Users\christa\AppData\Roaming\JAM Software
[2012.01.03 20:13:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TreeSize Free
[2012.01.03 20:13:42 | 000,000,000 | ---D | C] -- C:\Program Files\JAM Software
[2012.01.02 21:41:28 | 000,000,000 | ---D | C] -- C:\Program Files\Belarc
[2012.01.01 15:33:28 | 000,000,000 | ---D | C] -- C:\Windows\System32\directx
[2012.01.01 15:32:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SiSoftware
[2012.01.01 15:31:56 | 000,000,000 | ---D | C] -- C:\Program Files\SiSoftware
[2011.12.22 20:50:34 | 000,000,000 | ---D | C] -- C:\Program Files\MSECache
[2011.12.17 12:20:50 | 000,000,000 | ---D | C] -- C:\Windows\ISP
[2011.12.17 12:20:36 | 000,000,000 | ---D | C] -- C:\Users\christa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Circus
[2011.12.17 12:19:57 | 000,000,000 | ---D | C] -- C:\CIRCUS
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.01.06 13:50:59 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\christa\Desktop\OTL.exe
[2012.01.06 13:46:21 | 000,000,916 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.01.06 13:44:53 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.01.06 12:40:01 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.01.06 12:26:23 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.01.06 12:26:23 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.01.06 12:22:44 | 000,000,000 | ---- | M] () -- C:\Users\christa\defogger_reenable
[2012.01.06 12:19:14 | 000,050,477 | ---- | M] () -- C:\Users\christa\Desktop\Defogger.exe
[2012.01.06 12:01:06 | 000,002,527 | ---- | M] () -- C:\Users\christa\Desktop\HiJackThis.lnk
[2012.01.06 11:28:34 | 000,006,144 | ---- | M] () -- C:\Users\christa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.01.06 10:30:12 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.01.05 00:08:39 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012.01.05 00:07:11 | 000,628,742 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.01.05 00:07:11 | 000,595,996 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.01.05 00:07:11 | 000,126,260 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.01.05 00:07:11 | 000,104,070 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.01.04 21:33:56 | 000,001,017 | ---- | M] () -- C:\Users\christa\Desktop\procexp.lnk
[2011.12.31 17:34:50 | 000,000,284 | ---- | M] () -- C:\Windows\tasks\AppleSoftwareUpdate.job
[2011.12.25 16:16:27 | 000,000,085 | ---- | M] () -- C:\Windows\QTW.INI
[2011.12.19 14:57:21 | 000,112,579 | ---- | M] () -- C:\Users\christa\Desktop\Jahresrundbrief 2011_std.pdf
[2011.12.17 12:20:50 | 000,000,120 | ---- | M] () -- C:\Windows\isp.ini
[2011.12.17 03:09:37 | 000,318,216 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.12.11 19:02:25 | 002,861,852 | ---- | M] () -- C:\Users\christa\Desktop\England2011.pdf
[2011.12.10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.12.10 01:33:58 | 011,296,768 | ---- | M] () -- C:\Users\christa\AppData\Roaming\Sandra.mdb
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.01.06 13:46:21 | 000,000,916 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.01.06 12:22:44 | 000,000,000 | ---- | C] () -- C:\Users\christa\defogger_reenable
[2012.01.06 12:19:08 | 000,050,477 | ---- | C] () -- C:\Users\christa\Desktop\Defogger.exe
[2012.01.04 21:33:56 | 000,001,017 | ---- | C] () -- C:\Users\christa\Desktop\procexp.lnk
[2012.01.02 21:41:30 | 000,001,867 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
[2012.01.01 15:52:54 | 011,296,768 | ---- | C] () -- C:\Users\christa\AppData\Roaming\Sandra.mdb
[2011.12.19 14:57:18 | 000,112,579 | ---- | C] () -- C:\Users\christa\Desktop\Jahresrundbrief 2011_std.pdf
[2011.12.17 15:59:51 | 000,000,085 | ---- | C] () -- C:\Windows\QTW.INI
[2011.12.17 12:20:50 | 000,000,120 | ---- | C] () -- C:\Windows\isp.ini
[2011.12.17 12:19:59 | 000,003,888 | ---- | C] () -- C:\Windows\System\MCIQTENU.DLL
[2011.12.11 19:02:25 | 002,861,852 | ---- | C] () -- C:\Users\christa\Desktop\England2011.pdf
[2011.06.14 08:21:40 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010.09.06 21:53:39 | 000,017,408 | ---- | C] () -- C:\Users\christa\AppData\Local\WebpageIcons.db
[2010.08.06 17:40:38 | 000,000,680 | ---- | C] () -- C:\Users\christa\AppData\Local\d3d9caps.dat
[2010.06.07 18:33:15 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2009.09.25 16:06:34 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009.09.25 16:06:33 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.08.03 14:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009.08.03 14:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009.08.02 11:33:53 | 000,001,796 | ---- | C] () -- C:\Windows\cdplayer.ini
[2008.11.02 17:09:59 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008.05.26 22:57:48 | 000,000,600 | ---- | C] () -- C:\Users\christa\AppData\Local\PUTTY.RND
[2007.11.21 10:21:03 | 000,651,264 | ---- | C] () -- C:\Windows\System32\libeay32.dll
[2007.11.21 10:21:03 | 000,147,456 | ---- | C] () -- C:\Windows\System32\ssleay32.dll
[2007.11.21 10:21:03 | 000,110,592 | ---- | C] () -- C:\Windows\System32\AegisI5.exe
[2007.09.09 01:10:22 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html
[2007.06.24 11:37:46 | 000,006,144 | ---- | C] () -- C:\Users\christa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.06.23 18:34:01 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2007.06.21 17:15:03 | 000,000,000 | ---- | C] () -- C:\Users\christa\AppData\Roaming\wklnhst.dat
[2007.02.09 14:40:18 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2007.02.09 14:40:17 | 000,145,112 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2007.01.20 14:35:19 | 000,000,335 | ---- | C] () -- C:\Windows\nsreg.dat
[2007.01.18 13:47:20 | 000,098,304 | ---- | C] () -- C:\Windows\System32\MGHwCtrl.dll
[2007.01.18 13:47:20 | 000,032,768 | ---- | C] () -- C:\Windows\System32\MGFPCtrl.dll
[2007.01.18 13:47:20 | 000,024,576 | ---- | C] () -- C:\Windows\System32\MGPwrShm.dll
[2007.01.18 13:02:43 | 000,135,168 | ---- | C] () -- C:\Windows\System32\TXTUSER.EXE
[2007.01.18 12:45:41 | 000,103,024 | ---- | C] () -- C:\Windows\Unwise.exe
[2007.01.18 11:58:33 | 000,000,032 | ---- | C] () -- C:\Windows\CD_Start.INI
[2007.01.18 11:06:07 | 000,015,190 | ---- | C] () -- C:\Windows\M2000Twn.ini
[2007.01.18 10:29:04 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2006.11.02 16:38:05 | 000,628,742 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2006.11.02 16:38:05 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2006.11.02 16:38:05 | 000,126,260 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2006.11.02 16:38:05 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2006.11.02 13:53:49 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 13:44:53 | 000,318,216 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 11:33:01 | 000,595,996 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 11:33:01 | 000,104,070 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 11:25:44 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2006.11.02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006.10.31 17:37:00 | 000,114,688 | ---- | C] () -- C:\Windows\System32\TosBtAcc.dll
[2006.09.07 18:31:08 | 000,128,512 | ---- | C] () -- C:\Windows\chklogo6.exe
[2006.08.10 15:00:52 | 000,094,208 | ---- | C] () -- C:\Windows\System32\TosBtHcrpAPI.dll
[2006.04.20 07:34:24 | 000,193,584 | ---- | C] () -- C:\Windows\System32\CSGina.dll
[2005.07.22 21:30:20 | 000,065,536 | ---- | C] () -- C:\Windows\System32\TosCommAPI.dll
[2005.01.21 12:02:28 | 000,013,312 | ---- | C] () -- C:\Windows\System32\RMDevice.dll
 
========== LOP Check ==========
 
[2010.09.01 20:40:41 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\GARMIN
[2012.01.03 20:13:49 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\JAM Software
[2011.10.07 17:08:42 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Phase6
[2008.10.03 16:04:43 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Snapfish
[2008.05.01 17:36:53 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\T-Online
[2007.06.21 17:15:40 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Template
[2010.08.20 11:06:36 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Thunderbird
[2012.01.05 00:08:44 | 000,032,534 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %SYSTEMDRIVE%\*. >
[2007.06.21 15:43:58 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin
[2007.01.20 13:07:46 | 000,000,000 | ---D | M] -- C:\30bf431c1c23393eaa
[2009.10.28 13:10:20 | 000,000,000 | -HSD | M] -- C:\Boot
[2011.12.17 12:20:02 | 000,000,000 | ---D | M] -- C:\CIRCUS
[2006.11.02 13:59:44 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2007.06.21 15:39:33 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2012.01.06 11:58:53 | 000,000,000 | ---D | M] -- C:\Garmin
[2007.06.23 18:27:16 | 000,000,000 | RH-D | M] -- C:\MSOCache
[2008.07.28 10:16:22 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2012.01.06 11:59:32 | 000,000,000 | R--D | M] -- C:\Program Files
[2007.06.21 15:39:33 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2007.06.21 15:39:33 | 000,000,000 | -HSD | M] -- C:\Programme
[2012.01.06 14:00:19 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2012.01.01 15:33:30 | 000,000,000 | ---D | M] -- C:\TEMP
[2010.05.29 18:10:56 | 000,000,000 | R--D | M] -- C:\Users
[2012.01.06 12:01:39 | 000,000,000 | ---D | M] -- C:\Windows
 
< %PROGRAMFILES%\*.exe >
 
< %LOCALAPPDATA%\*.exe >
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.manifest /3 >
 
 
< MD5 for: AFD.SYS  >
[2011.04.21 14:58:27 | 000,273,408 | ---- | M] (Microsoft Corporation) MD5=3911B972B55FEA0478476B2E777B29FA -- C:\Windows\System32\drivers\afd.sys
[2011.04.21 14:58:27 | 000,273,408 | ---- | M] (Microsoft Corporation) MD5=3911B972B55FEA0478476B2E777B29FA -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6002.18457_none_d99fb42e5bb59d9b\afd.sys
[2011.04.21 14:16:42 | 000,273,408 | ---- | M] (Microsoft Corporation) MD5=48EB99503533C27AC6135648E5474457 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6001.18639_none_d7d0e0cc5e7d461c\afd.sys
[2006.11.02 09:58:43 | 000,270,336 | ---- | M] (Microsoft Corporation) MD5=5D24CAF8EFD924A875698FF28384DB8B -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6000.16386_none_d5b1809661820e7c\afd.sys
[2011.04.21 14:28:53 | 000,273,920 | ---- | M] (Microsoft Corporation) MD5=70EE0FC7A0F384DBD929A01384AEEB4B -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6002.22629_none_da4bc33774b91967\afd.sys
[2008.01.19 06:57:03 | 000,273,920 | ---- | M] (Microsoft Corporation) MD5=763E172A55177E478CB419F88FD0BA03 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6001.18000_none_d7e842925e6d1f50\afd.sys
[2009.04.11 05:47:03 | 000,273,920 | ---- | M] (Microsoft Corporation) MD5=A201207363AA900ABF1A388468688570 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6002.18005_none_d9d3bb9e5b8eea9c\afd.sys
[2011.04.21 14:12:21 | 000,273,920 | ---- | M] (Microsoft Corporation) MD5=C8AF25017CECB75906A571AC70D2D306 -- C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6001.22905_none_d876efff77862705\afd.sys
 
< MD5 for: EXPLORER.EXE  >
[2008.10.29 07:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008.10.29 07:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008.10.30 04:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2007.11.15 18:58:49 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2007.11.15 18:58:48 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe
[2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008.10.28 03:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006.11.02 10:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008.01.19 08:33:10 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
 
< MD5 for: REGEDIT.EXE  >
[2008.01.19 08:33:24 | 000,134,656 | ---- | M] (Microsoft Corporation) MD5=467A3B03E924B7B7EDD16D34740574B0 -- C:\Windows\regedit.exe
[2008.01.19 08:33:24 | 000,134,656 | ---- | M] (Microsoft Corporation) MD5=467A3B03E924B7B7EDD16D34740574B0 -- C:\Windows\winsxs\x86_microsoft-windows-registry-editor_31bf3856ad364e35_6.0.6001.18000_none_f42eb564dbd8a697\regedit.exe
[2006.11.02 10:45:35 | 000,134,656 | ---- | M] (Microsoft Corporation) MD5=F13123E76FDA33E55F11E0EB832E832A -- C:\Windows\winsxs\x86_microsoft-windows-registry-editor_31bf3856ad364e35_6.0.6000.16386_none_f1f7f368deed95c3\regedit.exe
 
< MD5 for: USERINIT.EXE  >
[2008.01.19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 10:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.19 08:33:37 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\System32\wininit.exe
[2008.01.19 08:33:37 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2006.11.02 10:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 10:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2011.12.24 17:50:20 | 000,182,856 | ---- | M] () MD5=B382935AB01B27D0E14F267DBF288896 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008.01.19 08:33:37 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-01-03 16:00:12
 
<          >

< End of report >


cosinus 07.01.2012 00:03

Bitte nun routinemäßig einen Vollscan mit malwarebytes machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Außerdem müssen alle Funde entfernt werden.

Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten!



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset





Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log

dieba 07.01.2012 11:43

Hallo Arne,
danke für die schnelle Antwort. Habe vollen MB Scan durchgeführt, hatte einen Fund (s.u.).
Wollte dann eset durchführen, bin aber mit folgendem Problem stecken geblieben: ESET wies auf 2 Störer hin (die ja ausgeschaltet werden sollen): Avira und Defender. Mir ist nicht klar, wie ich sie ausschalten soll: bei Defender finde ich keine Möglichkeit im Sicherheitscenter, genügt es unter den Defenderoptionen die automatische Überprüfung auszuschalten? Bei Avira hatte ich den Antivirguard deaktiviert, genügt das, weil mich ESET trotzdem auf Avira hingewiesen hat? und noch eine Frage: soll ich trotz beider Abschaltungen am Netz bleiben (notwendig wegen "online"-scan?). Anbei erst mal der neue MB-Scan (es gibt nur einen älteren vom 30.11., den ich im ersten posting schon im Anhang mitgeschickt hatte):

Code:

Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Datenbank Version: v2012.01.07.01

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
christa :: FREIZEIT [Administrator]

07.01.2012 09:03:40
mbam-log-2012-01-07 (09-03-40).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 288912
Laufzeit: 1 Stunde(n), 35 Minute(n), 35 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\Program Files\StartupRun\strun.exe (PUP.StartUpManager) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)


cosinus 07.01.2012 15:29

Ja bei Avira einfach den Guard deaktivieren.
Windows-Defender: Aktivieren und Deaktivieren von Windows Defender
Findet man ganz leicht via Google :pfeiff:

dieba 07.01.2012 15:33

danke!, mach ich gleich.
und am Netz bleiben oder nicht bei ESEt-Scan?

cosinus 07.01.2012 16:27

Immer im Internet bleiben. Es steht nichts davon dass du offeline sein sollst

dieba 07.01.2012 20:21

Hallo Arne,
hier jetzt das Ergebnis des ESET-Scans:

Code:

ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=6266d81321a59146a8a86d684cc241d9
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-07 06:32:18
# local_time=2012-01-07 07:32:18 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 130312821 130312821 0 0
# compatibility_mode=1797 16775165 100 100 619206 100845182 102964 0
# compatibility_mode=5892 16776574 100 100 4839 163481390 0 0
# compatibility_mode=8192 67108863 100 0 20823 20823 0 0
# scanned=186046
# found=2
# cleaned=0
# scan_time=12519
C:\Users\christa\Downloads\route_anzeigen.exe        a variant of Win32/Foxferi.A trojan (unable to clean)        00000000000000000000000000000000        I
E:\Christa\Users\christa\Downloads\route_anzeigen.exe        a variant of Win32/Foxferi.A trojan (unable to clean)        00000000000000000000000000000000        I


cosinus 07.01.2012 20:59

Zitat:

C:\Users\christa\Downloads\route_anzeigen.exe
Wo hast du diese Datei her?

dieba 07.01.2012 21:18

Habe gerade nochmal meine Frau gefragt, sie hat (jedenfalls nicht bewusst) diese Datei nicht heruntergeladen. Ich installiere ihr gelegentlich etwas, entweder von CD oder auch aus dem Netz heruntergeladen, kann mich aber auch nicht an so ein Programm oder den Download erinnern. Das "/Downloads"-Verzeichnis ist als Standard-download Ort für firefox eingestellt; könnte es sein, dass meine Frau ungewollt auf etwas geklickt hat?

Gruß, dieba

cosinus 07.01.2012 21:41

Lad die routen_anzeigen.exe bitte mal bei uns hoch => http://www.trojaner-board.de/54791-a...ner-board.html

dieba 07.01.2012 21:52

hochgeladen. Habe leider zu spät gesehen, dass ich Avira hätte ausschalten sollen.

cosinus 07.01.2012 21:58

Müsste ein Schädling sein => VirusTotal - Free Online Virus, Malware and URL Scanner

Antivir erkennt den noch nicht. Mal sehen was ThreatExpert zu dem Teil sagt.


Antivirus results
AhnLab-V3 - 2012.01.07.00 - 2012.01.07 - -
AntiVir - 7.11.20.194 - 2012.01.06 - -
Antiy-AVL - 2.0.3.7 - 2012.01.07 - -
Avast - 6.0.1289.0 - 2012.01.07 - Win32:Dropper-JQD [Drp]
AVG - 10.0.0.1190 - 2012.01.07 - Generic25.VAV
BitDefender - 7.2 - 2012.01.07 - -
ByteHero - 1.0.0.1 - 2011.12.31 - -
CAT-QuickHeal - 12.00 - 2012.01.07 - -
ClamAV - 0.97.3.0 - 2012.01.07 - -
Commtouch - 5.3.2.6 - 2012.01.07 - -
Comodo - 11205 - 2012.01.07 - -
DrWeb - 5.0.2.03300 - 2012.01.07 - -
Emsisoft - 5.1.0.11 - 2012.01.07 - Trojan.Win32.Foxferi!IK
eSafe - 7.0.17.0 - 2012.01.03 - Win32.Artemis
eTrust-Vet - 37.0.9668 - 2012.01.06 - -
F-Prot - 4.6.5.141 - 2012.01.07 - -
F-Secure - 9.0.16440.0 - 2012.01.07 - -
Fortinet - 4.3.388.0 - 2012.01.07 - -
GData - 22 - 2012.01.07 - Win32:Dropper-JQD
Ikarus - T3.1.1.109.0 - 2012.01.07 - Trojan.Win32.Foxferi
Jiangmin - 13.0.900 - 2012.01.07 - -
K7AntiVirus - 9.123.5881 - 2012.01.06 - Riskware
Kaspersky - 9.0.0.837 - 2012.01.07 - -
McAfee - 5.400.0.1158 - 2012.01.07 - Artemis!75FDE14D0A38
McAfee-GW-Edition - 2010.1E - 2012.01.07 - Artemis!75FDE14D0A38
Microsoft - 1.7903 - 2012.01.07 - Trojan:Win32/Foxferi.A
NOD32 - 6775 - 2012.01.07 - a variant of Win32/Foxferi.A
Norman - 6.07.13 - 2012.01.07 - W32/Suspicious_Gen2.SQGJX
nProtect - 2012-01-07.01 - 2012.01.07 - -
Panda - 10.0.3.5 - 2012.01.07 - -
PCTools - 8.0.0.5 - 2012.01.07 - -
Prevx - 3.0 - 2012.01.07 - -
Rising - 23.91.04.02 - 2012.01.06 - -
Sophos - 4.73.0 - 2012.01.07 - -
SUPERAntiSpyware - 4.40.0.1006 - 2012.01.07 - -
Symantec - 20111.2.0.82 - 2012.01.07 - -
TheHacker - 6.7.0.1.373 - 2012.01.06 - -
TrendMicro - 9.500.0.1008 - 2012.01.07 - -
TrendMicro-HouseCall - 9.500.0.1008 - 2012.01.07 - -
VBA32 - 3.12.16.4 - 2012.01.06 - -
VIPRE - 11365 - 2012.01.07 - Trojan.Win32.Generic!BT
ViRobot - 2012.1.7.4869 - 2012.01.07 - -
VirusBuster - 14.1.155.0 - 2012.01.07 - Trojan.Foxferi!Jz10v/O+yNE
File info:
MD5: 75fde14d0a38d0f1b8cae7dd54c58ff7
SHA1: 95a74475fcfa2a1f53bbfab36cc308d6e0982783
SHA256: 6f4952b3426c559c78821c0a8a96955c9a63bf2076d0f912dcf4f26add85cb7f
File size: 263527 bytes
Scan date: 2012-01-07 20:48:18 (UTC)

dieba 07.01.2012 22:23

?soll ich warten oder was unternehmen?

Gruß, dieba

cosinus 07.01.2012 23:28

Hier ist der Bericht von Threatexpert => ThreatExpert Report: Trojan.Win32.Foxferi

Mach bitte ein neues OTL-Log. Bitte alles nach Möglichkeit hier in CODE-Tags posten.

Wird so gemacht:

[code] hier steht das Log [/code]

Und das ganze sieht dann so aus:

Code:

hier steht das Log
CustomScan mit OTL

Falls noch nicht vorhanden, lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
Code:

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
/md5start
wininit.exe
userinit.exe
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
ws2ifsl.sys
sceclt.dll
ntelogon.dll
winlogon.exe
logevent.dll
user32.DLL
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
/md5stop
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
CREATERESTOREPOINT


dieba 08.01.2012 02:22

noch so spät aktiv? Toll!
OTL-Scan wie gewünscht:

Code:

OTL logfile created on: 08.01.2012 01:53:10 - Run 2
OTL by OldTimer - Version 3.2.31.0    Folder = C:\Users\christa\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
894,71 Mb Total Physical Memory | 387,73 Mb Available Physical Memory | 43,34% Memory free
3,84 Gb Paging File | 3,14 Gb Available in Paging File | 81,89% Paging File free
Paging file location(s): c:\pagefile.sys 3072 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 101,57 Gb Total Space | 50,54 Gb Free Space | 49,75% Space Free | Partition Type: NTFS
Drive E: | 465,73 Gb Total Space | 214,95 Gb Free Space | 46,15% Space Free | Partition Type: NTFS
 
Computer Name: FREIZEIT | User Name: christa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012.01.06 13:50:59 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\christa\Desktop\OTL.exe
PRC - [2011.07.01 11:03:22 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.04.28 11:54:41 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2010.11.30 18:12:37 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010.01.14 21:10:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.04.11 07:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2008.01.19 08:38:38 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Defender\MSASCui.exe
PRC - [2006.12.29 11:11:00 | 004,317,184 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2006.10.31 22:40:16 | 000,077,824 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
PRC - [2006.10.19 14:42:00 | 000,065,536 | ---- | M] (O2Micro International) -- C:\Windows\System32\o2flash.exe
PRC - [2006.03.22 11:07:22 | 000,040,960 | ---- | M] () -- C:\Programme\System Control Manager\edd.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2007.01.08 12:08:56 | 000,159,744 | ---- | M] () -- C:\Windows\System32\atitmmxx.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2011.07.01 11:03:22 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.04.28 11:54:41 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2008.12.12 03:20:08 | 000,095,896 | ---- | M] (SiSoftware) [Disabled | Stopped] -- C:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP1\RpcAgentSrv.exe -- (SandraAgentSrv)
SRV - [2008.10.23 16:45:14 | 000,307,200 | ---- | M] (T-Systems Enterprise Services GmbH) [On_Demand | Stopped] -- C:\Program Files\DSL-Manager\DslMgrSvc.exe -- (TDslMgrService)
SRV - [2008.01.19 08:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2006.10.31 22:40:16 | 000,077,824 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
SRV - [2006.10.23 13:50:35 | 000,046,640 | R--- | M] (AOL LLC) [Disabled | Stopped] -- C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe -- (AOL ACS)
SRV - [2006.10.19 14:42:00 | 000,065,536 | ---- | M] (O2Micro International) [Auto | Running] -- C:\Windows\System32\o2flash.exe -- (O2Flash)
SRV - [2006.03.22 11:07:22 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\Programme\System Control Manager\edd.exe -- (NishService)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011.07.01 11:03:26 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.07.01 11:03:26 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010.06.17 14:27:02 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.08.07 22:46:56 | 000,023,112 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- C:\Programme\SiSoftware\SiSoftware Sandra Lite 2012.SP1\WNt500x86\sandra.sys -- (SANDRA)
DRV - [2009.02.13 11:35:01 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Programme\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2007.11.22 11:06:08 | 000,893,440 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athrusb.sys -- (athrusb)
DRV - [2007.11.21 10:21:06 | 000,015,890 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\mdc8021x.sys -- (MDC8021X) AEGIS Protocol (IEEE 802.1x)
DRV - [2007.09.12 17:24:00 | 000,026,816 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DslTestSp5.sys -- (dsltestSp5)
DRV - [2007.08.01 15:49:00 | 000,016,448 | ---- | M] (T-Systems Enterprise Services GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\dslmnlwf.sys -- (DslMNLwf)
DRV - [2007.05.11 15:28:30 | 000,357,376 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\netr61.sys -- (rt61x86)
DRV - [2007.01.19 09:41:06 | 000,077,824 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGR1310_60.sys -- (AGR1310_60)
DRV - [2007.01.08 12:16:50 | 002,313,216 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2006.11.30 16:30:30 | 000,811,440 | ---- | M] (Bison Electronics. Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\BisonCam.sys -- (Cam5603D)
DRV - [2006.11.20 15:14:08 | 000,038,400 | ---- | M] (O2Micro ) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\o2media.sys -- (O2MDRDR)
DRV - [2006.11.17 13:58:32 | 000,031,360 | ---- | M] (O2Micro ) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\o2sd.sys -- (O2SDRDR)
DRV - [2006.11.02 08:41:50 | 000,983,552 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006.11.01 21:18:15 | 000,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - [2006.10.28 00:29:10 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2006.10.05 16:07:46 | 000,073,600 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TosRfhid.sys -- (Tosrfhid)
DRV - [2006.09.21 14:22:42 | 000,113,920 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TosRfbd.sys -- (tosrfbd)
DRV - [2006.07.10 15:17:48 | 000,016,896 | ---- | M] (WideView Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BDA_Loader_220A.sys -- (BDA_Loader_220A)
DRV - [2006.07.03 10:31:26 | 000,009,088 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\MGHwCtrl.sys -- (MGHwCtrl)
DRV - [2005.08.18 18:22:30 | 000,110,080 | ---- | M] (Deterministic Networks, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\dne2000.sys -- (DNE)
DRV - [2005.08.01 16:45:08 | 000,064,896 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2005.05.17 03:51:34 | 000,005,315 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CVirtA.sys -- (CVirtA)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.juelich.de/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.selectedEngine: "Google Deutschland"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hxxp://www.juelich.de/stabue/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.5
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {53A03D43-5363-4669-8190-99061B2DEBA5}:1.4.3
FF - prefs.js..extensions.enabledItems: ietab@ip.cn:1.98.20110322
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.01.04 12:33:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.04.03 18:34:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011.10.13 20:35:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
 
[2010.08.20 11:06:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\christa\AppData\Roaming\mozilla\Extensions
[2010.08.20 11:06:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\christa\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012.01.06 14:21:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\christa\AppData\Roaming\mozilla\Firefox\Profiles\8p6t23gq.default\extensions
[2010.05.24 10:07:42 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\christa\AppData\Roaming\mozilla\Firefox\Profiles\8p6t23gq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.12.14 19:23:23 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\christa\AppData\Roaming\mozilla\Firefox\Profiles\8p6t23gq.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011.11.12 18:02:53 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\christa\AppData\Roaming\mozilla\Firefox\Profiles\8p6t23gq.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011.03.26 20:52:04 | 000,000,000 | ---D | M] (IE Tab Plus) -- C:\Users\christa\AppData\Roaming\mozilla\Firefox\Profiles\8p6t23gq.default\extensions\ietab@ip.cn
[2012.01.03 17:22:08 | 000,002,128 | ---- | M] () -- C:\Users\christa\AppData\Roaming\Mozilla\Firefox\Profiles\8p6t23gq.default\searchplugins\booklooker.xml
[2012.01.03 17:22:08 | 000,005,203 | ---- | M] () -- C:\Users\christa\AppData\Roaming\Mozilla\Firefox\Profiles\8p6t23gq.default\searchplugins\buchticket-autorensuche.xml
[2012.01.03 17:22:09 | 000,002,454 | ---- | M] () -- C:\Users\christa\AppData\Roaming\Mozilla\Firefox\Profiles\8p6t23gq.default\searchplugins\google-deutschland.xml
[2012.01.03 17:22:09 | 000,002,786 | ---- | M] () -- C:\Users\christa\AppData\Roaming\Mozilla\Firefox\Profiles\8p6t23gq.default\searchplugins\google-images.xml
[2012.01.03 17:22:09 | 000,002,007 | ---- | M] () -- C:\Users\christa\AppData\Roaming\Mozilla\Firefox\Profiles\8p6t23gq.default\searchplugins\leo-en-de.xml
[2012.01.04 12:33:43 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
() (No name found) -- C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\EXTENSIONS\{53A03D43-5363-4669-8190-99061B2DEBA5}.XPI
() (No name found) -- C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\EXTENSIONS\{CE6E6E3B-84DD-4CAC-9F63-8D2AE4F30A4B}.XPI
() (No name found) -- C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012.01.04 12:33:39 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012.01.04 12:33:35 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.01.04 12:33:35 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.01.04 12:33:35 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.01.04 12:33:35 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.01.04 12:33:35 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.01.04 12:33:35 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - Startup: C:\Users\christa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2011.11.10 11:20:39 | 000,000,000 | -H-D | M]
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - C:\Programme\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Öffnen mit WordPerfect - C:\Programme\WordPerfect Office X3\Programs\WPLauncher.hta ()
O9 - Extra 'Tools' menuitem : Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} hxxp://www3.snapfish.de/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0C1F45C5-0DFA-4E69-87DD-49FAC983ED1C}: DhcpNameServer = 172.16.15.254 10.0.0.138 194.109.6.66
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1F988EA9-9DF7-4BEE-B4D9-821228261E1C}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{63875ECE-B993-498D-8FA7-8E83293B6696}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B2965EE1-3C04-423A-A5A1-A3197B0707FA}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\AutorunsDisabled - No CLSID value found
O18 - Protocol\Handler\AutorunsDisabled\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\AutorunsDisabled\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\AutorunsDisabled\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\AutorunsDisabled\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Programme\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\AutorunsDisabled - No CLSID value found
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 16777216
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: FastUserSwitchingCompatibility -  File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla -  File not found
NetSvcs: Ntmssvc -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: SRService -  File not found
NetSvcs: WmdmPmSp -  File not found
NetSvcs: LogonHours -  File not found
NetSvcs: PCAudit -  File not found
NetSvcs: helpsvc -  File not found
NetSvcs: uploadmgr -  File not found
 
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^phase-6 Reminder.lnk - C:\Programme\phase-6\phase-6-basic\reminder\reminder.exe - (phase-6)
MsConfig - StartUpReg: Adobe ARM - hkey= - key= -  File not found
MsConfig - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: Malwarebytes' Anti-Malware (reboot) - hkey= - key= - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
MsConfig - StartUpReg: Sidebar - hkey= - key= -  File not found
MsConfig - StartUpReg: Skype - hkey= - key= -  File not found
MsConfig - StartUpReg: SpybotSD TeaTimer - hkey= - key= - C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
MsConfig - StartUpReg: swg - hkey= - key= - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
MsConfig - State: "startup" - 2
MsConfig - State: "services" - 0
 
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS -  File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS -  File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Webordner
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Macromedia Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: AutorunsDisabled -
ActiveX: ccc-core-static - msiexec /fums {AA696568-50B5-9FAA-60D7-9C333239C3A4} /qb
 
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\divx.dll (DivXNetworks, Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012.01.07 11:16:35 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012.01.07 11:09:34 | 002,322,184 | ---- | C] (ESET) -- C:\Users\christa\Desktop\esetsmartinstaller_enu.exe
[2012.01.06 13:50:53 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\christa\Desktop\OTL.exe
[2012.01.04 21:10:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012.01.04 21:10:10 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2012.01.04 18:10:51 | 000,000,000 | ---D | C] -- C:\Users\christa\!!Systemänderungen
[2012.01.04 17:29:07 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled
[2012.01.03 20:13:49 | 000,000,000 | ---D | C] -- C:\Users\christa\AppData\Roaming\JAM Software
[2012.01.03 20:13:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TreeSize Free
[2012.01.03 20:13:42 | 000,000,000 | ---D | C] -- C:\Program Files\JAM Software
[2012.01.02 21:41:28 | 000,000,000 | ---D | C] -- C:\Program Files\Belarc
[2012.01.01 15:33:28 | 000,000,000 | ---D | C] -- C:\Windows\System32\directx
[2012.01.01 15:32:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SiSoftware
[2012.01.01 15:31:56 | 000,000,000 | ---D | C] -- C:\Program Files\SiSoftware
[2011.12.22 20:50:34 | 000,000,000 | ---D | C] -- C:\Program Files\MSECache
[2011.12.17 12:20:50 | 000,000,000 | ---D | C] -- C:\Windows\ISP
[2011.12.17 12:20:36 | 000,000,000 | ---D | C] -- C:\Users\christa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Circus
[2011.12.17 12:19:57 | 000,000,000 | ---D | C] -- C:\CIRCUS
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012.01.08 01:46:30 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.01.08 01:45:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.01.07 19:41:37 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.01.07 19:41:37 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.01.07 19:40:09 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.01.07 16:33:40 | 000,000,284 | ---- | M] () -- C:\Windows\tasks\AppleSoftwareUpdate.job
[2012.01.07 15:49:35 | 002,322,184 | ---- | M] (ESET) -- C:\Users\christa\Desktop\esetsmartinstaller_enu.exe
[2012.01.07 11:16:42 | 000,628,742 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012.01.07 11:16:42 | 000,595,996 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.01.07 11:16:42 | 000,126,260 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012.01.07 11:16:42 | 000,104,070 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.01.07 10:55:33 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012.01.07 08:44:07 | 000,310,048 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.01.06 17:19:47 | 000,014,215 | ---- | M] () -- C:\Users\christa\Desktop\Logfiles.zip
[2012.01.06 14:22:34 | 000,302,592 | ---- | M] () -- C:\Users\christa\Desktop\3c5dcupk.exe
[2012.01.06 13:50:59 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\christa\Desktop\OTL.exe
[2012.01.06 13:46:21 | 000,000,916 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.01.06 12:22:44 | 000,000,000 | ---- | M] () -- C:\Users\christa\defogger_reenable
[2012.01.06 12:19:14 | 000,050,477 | ---- | M] () -- C:\Users\christa\Desktop\Defogger.exe
[2012.01.06 12:01:06 | 000,002,527 | ---- | M] () -- C:\Users\christa\Desktop\HiJackThis.lnk
[2012.01.06 11:28:34 | 000,006,144 | ---- | M] () -- C:\Users\christa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.01.04 21:33:56 | 000,001,017 | ---- | M] () -- C:\Users\christa\Desktop\procexp.lnk
[2011.12.25 16:16:27 | 000,000,085 | ---- | M] () -- C:\Windows\QTW.INI
[2011.12.19 14:57:21 | 000,112,579 | ---- | M] () -- C:\Users\christa\Desktop\Jahresrundbrief 2011_std.pdf
[2011.12.17 12:20:50 | 000,000,120 | ---- | M] () -- C:\Windows\isp.ini
[2011.12.11 19:02:25 | 002,861,852 | ---- | M] () -- C:\Users\christa\Desktop\England2011.pdf
[2011.12.10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011.12.10 01:33:58 | 011,296,768 | ---- | M] () -- C:\Users\christa\AppData\Roaming\Sandra.mdb
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012.01.06 17:17:57 | 000,014,215 | ---- | C] () -- C:\Users\christa\Desktop\Logfiles.zip
[2012.01.06 14:22:30 | 000,302,592 | ---- | C] () -- C:\Users\christa\Desktop\3c5dcupk.exe
[2012.01.06 13:46:21 | 000,000,916 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.01.06 12:22:44 | 000,000,000 | ---- | C] () -- C:\Users\christa\defogger_reenable
[2012.01.06 12:19:08 | 000,050,477 | ---- | C] () -- C:\Users\christa\Desktop\Defogger.exe
[2012.01.04 21:33:56 | 000,001,017 | ---- | C] () -- C:\Users\christa\Desktop\procexp.lnk
[2012.01.02 21:41:30 | 000,001,867 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
[2012.01.01 15:52:54 | 011,296,768 | ---- | C] () -- C:\Users\christa\AppData\Roaming\Sandra.mdb
[2011.12.19 14:57:18 | 000,112,579 | ---- | C] () -- C:\Users\christa\Desktop\Jahresrundbrief 2011_std.pdf
[2011.12.17 15:59:51 | 000,000,085 | ---- | C] () -- C:\Windows\QTW.INI
[2011.12.17 12:20:50 | 000,000,120 | ---- | C] () -- C:\Windows\isp.ini
[2011.12.17 12:19:59 | 000,003,888 | ---- | C] () -- C:\Windows\System\MCIQTENU.DLL
[2011.12.11 19:02:25 | 002,861,852 | ---- | C] () -- C:\Users\christa\Desktop\England2011.pdf
[2011.06.14 08:21:40 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010.09.06 21:53:39 | 000,017,408 | ---- | C] () -- C:\Users\christa\AppData\Local\WebpageIcons.db
[2010.08.06 17:40:38 | 000,000,680 | ---- | C] () -- C:\Users\christa\AppData\Local\d3d9caps.dat
[2010.06.07 18:33:15 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2009.09.25 16:06:34 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009.09.25 16:06:33 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.08.03 14:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009.08.03 14:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009.08.02 11:33:53 | 000,001,796 | ---- | C] () -- C:\Windows\cdplayer.ini
[2008.11.02 17:09:59 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008.05.26 22:57:48 | 000,000,600 | ---- | C] () -- C:\Users\christa\AppData\Local\PUTTY.RND
[2007.11.21 10:21:03 | 000,651,264 | ---- | C] () -- C:\Windows\System32\libeay32.dll
[2007.11.21 10:21:03 | 000,147,456 | ---- | C] () -- C:\Windows\System32\ssleay32.dll
[2007.11.21 10:21:03 | 000,110,592 | ---- | C] () -- C:\Windows\System32\AegisI5.exe
[2007.09.09 01:10:22 | 000,000,305 | ---- | C] () -- C:\ProgramData\addr_file.html
[2007.06.24 11:37:46 | 000,006,144 | ---- | C] () -- C:\Users\christa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.06.23 18:34:01 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI
[2007.06.21 17:15:03 | 000,000,000 | ---- | C] () -- C:\Users\christa\AppData\Roaming\wklnhst.dat
[2007.02.09 14:40:18 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2007.02.09 14:40:17 | 000,145,112 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2007.01.20 14:35:19 | 000,000,335 | ---- | C] () -- C:\Windows\nsreg.dat
[2007.01.18 13:47:20 | 000,098,304 | ---- | C] () -- C:\Windows\System32\MGHwCtrl.dll
[2007.01.18 13:47:20 | 000,032,768 | ---- | C] () -- C:\Windows\System32\MGFPCtrl.dll
[2007.01.18 13:47:20 | 000,024,576 | ---- | C] () -- C:\Windows\System32\MGPwrShm.dll
[2007.01.18 13:02:43 | 000,135,168 | ---- | C] () -- C:\Windows\System32\TXTUSER.EXE
[2007.01.18 12:45:41 | 000,103,024 | ---- | C] () -- C:\Windows\Unwise.exe
[2007.01.18 11:58:33 | 000,000,032 | ---- | C] () -- C:\Windows\CD_Start.INI
[2007.01.18 11:06:07 | 000,015,190 | ---- | C] () -- C:\Windows\M2000Twn.ini
[2007.01.18 10:29:04 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2006.11.02 16:38:05 | 000,628,742 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2006.11.02 16:38:05 | 000,290,748 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2006.11.02 16:38:05 | 000,126,260 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2006.11.02 16:38:05 | 000,036,916 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2006.11.02 13:53:49 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 13:44:53 | 000,310,048 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 11:33:01 | 000,595,996 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 11:33:01 | 000,104,070 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 11:25:44 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2006.11.02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006.10.31 17:37:00 | 000,114,688 | ---- | C] () -- C:\Windows\System32\TosBtAcc.dll
[2006.09.07 18:31:08 | 000,128,512 | ---- | C] () -- C:\Windows\chklogo6.exe
[2006.08.10 15:00:52 | 000,094,208 | ---- | C] () -- C:\Windows\System32\TosBtHcrpAPI.dll
[2006.04.20 07:34:24 | 000,193,584 | ---- | C] () -- C:\Windows\System32\CSGina.dll
[2005.07.22 21:30:20 | 000,065,536 | ---- | C] () -- C:\Windows\System32\TosCommAPI.dll
[2005.01.21 12:02:28 | 000,013,312 | ---- | C] () -- C:\Windows\System32\RMDevice.dll
 
========== LOP Check ==========
 
[2010.09.01 20:40:41 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\GARMIN
[2012.01.03 20:13:49 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\JAM Software
[2011.10.07 17:08:42 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Phase6
[2008.10.03 16:04:43 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Snapfish
[2008.05.01 17:36:53 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\T-Online
[2007.06.21 17:15:40 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Template
[2010.08.20 11:06:36 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Thunderbird
[2012.01.07 10:55:33 | 000,032,534 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
 
< %ALLUSERSPROFILE%\Application Data\*. >
 
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
 
< %APPDATA%\*. >
[2010.06.07 18:57:32 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Adobe
[2009.06.09 16:30:59 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Ahead
[2007.06.21 15:44:20 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\ATI
[2010.12.16 17:57:50 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Avira
[2007.08.20 21:57:38 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Corel
[2007.06.21 16:55:53 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Corel Photo Album
[2008.05.17 18:52:33 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\CyberLink
[2010.09.01 20:40:41 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\GARMIN
[2008.12.21 15:07:04 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Google
[2007.06.21 15:43:43 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Identities
[2009.06.18 21:49:28 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\InstallShield
[2012.01.03 20:13:49 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\JAM Software
[2007.08.19 21:02:41 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Macromedia
[2011.11.30 00:06:40 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Malwarebytes
[2011.12.22 20:55:11 | 000,000,000 | --SD | M] -- C:\Users\christa\AppData\Roaming\Microsoft
[2009.09.06 22:11:54 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\mIRC
[2011.10.07 17:08:59 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Mozilla
[2011.10.07 17:08:42 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Phase6
[2011.06.18 23:31:31 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Skype
[2011.06.18 23:06:57 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\skypePM
[2008.05.26 23:15:05 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\SmartFTP
[2008.10.03 16:04:43 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Snapfish
[2008.05.01 17:36:53 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\T-Online
[2007.06.21 17:15:40 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Template
[2010.08.20 11:06:36 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Thunderbird
[2011.11.20 17:08:17 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\vlc
[2007.06.23 20:06:29 | 000,000,000 | ---D | M] -- C:\Users\christa\AppData\Roaming\Winamp
 
< %APPDATA%\*.exe /s >
[2010.02.01 02:45:40 | 000,038,784 | ---- | M] () -- C:\Users\christa\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2007.06.23 22:17:51 | 000,026,694 | R--- | M] () -- C:\Users\christa\AppData\Roaming\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\ARPPRODUCTICON.exe
[2007.06.23 22:17:51 | 000,026,694 | R--- | M] () -- C:\Users\christa\AppData\Roaming\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
[2007.06.23 22:17:51 | 000,026,694 | R--- | M] () -- C:\Users\christa\AppData\Roaming\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
[2007.06.23 22:17:51 | 000,026,694 | R--- | M] () -- C:\Users\christa\AppData\Roaming\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\UNINST_Uninstall_G_3DE5E7D47B88403CA3FD2017A8240C5B.exe
[2010.06.07 18:12:26 | 000,388,096 | R--- | M] (Trend Micro Inc.) -- C:\Users\christa\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
 
< %SYSTEMDRIVE%\*.exe >
 
 
< MD5 for: AGP440.SYS  >
[2008.01.19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006.11.02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys
[2006.11.02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
 
< MD5 for: ATAPI.SYS  >
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.15 16:31:28 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=224505155EC3E36D7A1F36E446F04C2A -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_ecc53ff9\atapi.sys
[2008.01.15 16:31:28 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=224505155EC3E36D7A1F36E446F04C2A -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16584_none_daff695624a08568\atapi.sys
[2008.01.19 08:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.19 08:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 10:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.01.15 16:31:27 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=BFD3DF48C9ED81934FE21E8E3CFC2496 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20707_none_dbe288453d7a8ed6\atapi.sys
 
< MD5 for: CNGAUDIT.DLL  >
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006.11.02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
 
< MD5 for: IASTORV.SYS  >
[2008.01.19 08:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.19 08:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys
[2006.11.02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
 
< MD5 for: NETLOGON.DLL  >
[2006.11.02 10:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009.04.11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.19 08:35:36 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
 
< MD5 for: NVSTOR.SYS  >
[2006.11.02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\drivers\nvstor.sys
[2006.11.02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.19 08:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.19 08:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
 
< MD5 for: SCECLI.DLL  >
[2008.01.19 08:36:19 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006.11.02 10:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009.04.11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
 
< MD5 for: USER32.DLL  >
[2007.06.24 10:28:24 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=63B4F59D7C89B1BF5277F1FFEFD491CD -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16438_none_cb39bc5b7047127e\user32.dll
[2007.06.24 10:28:24 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=9D9F061EDA75425FC67F0365E3467C86 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.20537_none_cbc258dc896598f1\user32.dll
[2008.01.19 08:36:46 | 000,627,200 | ---- | M] (Microsoft Corporation) MD5=B974D9F06DC7D1908E825DC201681269 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6001.18000_none_cd386c416d5c7f32\user32.dll
[2006.11.02 10:46:13 | 000,633,856 | ---- | M] (Microsoft Corporation) MD5=E698A5437B89A285ACA3FF022356810A -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6000.16386_none_cb01aa4570716e5e\user32.dll
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\user32.dll
[2009.04.11 07:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2008.01.19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008.01.19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006.11.02 10:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
 
< MD5 for: WININIT.EXE  >
[2008.01.19 08:33:37 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\System32\wininit.exe
[2008.01.19 08:33:37 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=101BA3EA053480BB5D957EF37C06B5ED -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
[2006.11.02 10:45:57 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=D4385B03E8CCCEE6F0EE249F827C1F3E -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6000.16386_none_2ebbf6d3076595ce\wininit.exe
 
< MD5 for: WINLOGON.EXE  >
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009.04.11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006.11.02 10:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2011.12.24 17:50:20 | 000,182,856 | ---- | M] () MD5=B382935AB01B27D0E14F267DBF288896 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008.01.19 08:33:37 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
 
< MD5 for: WS2IFSL.SYS  >
[2006.11.02 09:58:26 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=84620AECDCFD2A7A14E6263927D8C0ED -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6000.16386_none_4d4fded8cae2956d\ws2ifsl.sys
[2008.01.19 06:56:49 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2008.01.19 06:56:49 | 000,015,872 | ---- | M] (Microsoft Corporation) MD5=E3A3CB253C0EC2494D4A61F5E43A389C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.0.6001.18000_none_4f86a0d4c7cda641\ws2ifsl.sys
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< %systemroot%\System32\config\*.sav >
[2006.11.02 11:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2006.11.02 11:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2006.11.02 11:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 11:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 11:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
 
< %systemroot%\*. /mp /s >
 
< %systemroot%\system32\*.dll /lockedfiles >
 
<          >

< End of report >


cosinus 08.01.2012 02:40

Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!)

Hinweis: Falls Du Deinen Benutzernamen unkenntlich gemacht hast, musst Du das Ausgesternte in Deinen richtigen Benutzernamen wieder verwandeln, sonst funktioniert das Script nicht!!

Code:

:OTL
O32 - HKLM CDRom: AutoRun - 16777216
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
MsConfig - StartUpReg: SpybotSD TeaTimer - hkey= - key= - C:\Programme\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
:Commands
[emptytemp]
[resethosts]

Klick dann oben links auf den Button Fix!
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet.

Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.

Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!

dieba 08.01.2012 14:53

Hallo Arne,
hoffentlich gut und lang geschlafen:sleepy:
hier der OTL-Scan:

Code:

All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\SpybotSD TeaTimer\ deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: christa
->Temp folder emptied: 631934261 bytes
->Temporary Internet Files folder emptied: 116393240 bytes
->Java cache emptied: 35533129 bytes
->FireFox cache emptied: 91036067 bytes
->Flash cache emptied: 257348 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41620 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: dieter
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1353257 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 205095327 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 1.032,00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.31.0 log created on 01082012_142114

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

Gruß, dieba

cosinus 08.01.2012 20:52

Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.
Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg


Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, Verknüpfungen auf dem Desktop oder im Startmenü unter "alle Programme" fehlen, bitte unhide ausführen:
Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop.
Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern )
http://www.trojaner-board.de/images/icons/icon4.gif Windows-Vista und Windows-7-User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif

dieba 08.01.2012 22:00

Hallo Arne,
in http://www.trojaner-board.de/82358-t...entfernen.html steht "alle Programme schließen" vor Ausführung von TDSSKiller. Gehören dazu auch Defender und Antivir-Guard oder nur die "normalen" wie browser und andere Benutzeranwendungen.

Gruß, dieba

cosinus 08.01.2012 22:18

Ja undebedingt auch Virenscanner deaktivieren

dieba 08.01.2012 22:27

Hier das Ergebnis:

Code:

22:03:25.0914 1172        TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
22:03:26.0149 1172        ============================================================
22:03:26.0149 1172        Current date / time: 2012/01/08 22:03:26.0149
22:03:26.0149 1172        SystemInfo:
22:03:26.0149 1172       
22:03:26.0149 1172        OS Version: 6.0.6002 ServicePack: 2.0
22:03:26.0149 1172        Product type: Workstation
22:03:26.0149 1172        ComputerName: FREIZEIT
22:03:26.0164 1172        UserName: christa
22:03:26.0164 1172        Windows directory: C:\Windows
22:03:26.0164 1172        System windows directory: C:\Windows
22:03:26.0164 1172        Processor architecture: Intel x86
22:03:26.0164 1172        Number of processors: 1
22:03:26.0164 1172        Page size: 0x1000
22:03:26.0164 1172        Boot type: Normal boot
22:03:26.0164 1172        ============================================================
22:03:27.0586 1172        Initialize success
22:23:48.0017 3864        ============================================================
22:23:48.0017 3864        Scan started
22:23:48.0017 3864        Mode: Manual; SigCheck; TDLFS;
22:23:48.0017 3864        ============================================================
22:23:49.0579 3864        ACPI            (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
22:23:49.0751 3864        ACPI - ok
22:23:49.0829 3864        adp94xx        (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys
22:23:49.0861 3864        adp94xx - ok
22:23:49.0986 3864        adpahci        (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys
22:23:50.0001 3864        adpahci - ok
22:23:50.0064 3864        adpu160m        (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys
22:23:50.0079 3864        adpu160m - ok
22:23:50.0126 3864        adpu320        (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys
22:23:50.0142 3864        adpu320 - ok
22:23:50.0345 3864        AFD            (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys
22:23:50.0439 3864        AFD - ok
22:23:50.0548 3864        AgereSoftModem  (5d97943c128ed756d1b0a08302c1b1f8) C:\Windows\system32\DRIVERS\AGRSM.sys
22:23:50.0861 3864        AgereSoftModem - ok
22:23:51.0064 3864        agp440          (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys
22:23:51.0079 3864        agp440 - ok
22:23:51.0157 3864        AGR1310_60      (0fb81a051fe8ac47c0a54db2f0901b98) C:\Windows\system32\DRIVERS\AGR1310_60.sys
22:23:51.0220 3864        AGR1310_60 - ok
22:23:51.0376 3864        aic78xx        (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
22:23:51.0407 3864        aic78xx - ok
22:23:51.0486 3864        aliide          (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys
22:23:51.0517 3864        aliide - ok
22:23:51.0579 3864        amdagp          (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys
22:23:51.0611 3864        amdagp - ok
22:23:51.0657 3864        amdide          (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys
22:23:51.0673 3864        amdide - ok
22:23:51.0845 3864        AmdK7          (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys
22:23:51.0986 3864        AmdK7 - ok
22:23:52.0048 3864        AmdK8          (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys
22:23:52.0111 3864        AmdK8 - ok
22:23:52.0298 3864        AR5523 - ok
22:23:52.0361 3864        arc            (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys
22:23:52.0376 3864        arc - ok
22:23:52.0423 3864        arcsas          (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys
22:23:52.0439 3864        arcsas - ok
22:23:52.0532 3864        AsyncMac        (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
22:23:52.0579 3864        AsyncMac - ok
22:23:52.0720 3864        atapi          (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
22:23:52.0720 3864        atapi - ok
22:23:52.0767 3864        ATHFMWDL - ok
22:23:52.0907 3864        athrusb        (569059302103fbf6774a2ea9c3454910) C:\Windows\system32\DRIVERS\athrusb.sys
22:23:53.0048 3864        athrusb ( UnsignedFile.Multi.Generic ) - warning
22:23:53.0048 3864        athrusb - detected UnsignedFile.Multi.Generic (1)
22:23:53.0267 3864        avgio          (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Program Files\Avira\AntiVir Desktop\avgio.sys
22:23:53.0298 3864        avgio - ok
22:23:53.0423 3864        avgntflt        (1e4114685de1ffa9675e09c6a1fb3f4b) C:\Windows\system32\DRIVERS\avgntflt.sys
22:23:53.0814 3864        avgntflt - ok
22:23:53.0907 3864        avipbb          (0f78d3dae6dedd99ae54c9491c62adf2) C:\Windows\system32\DRIVERS\avipbb.sys
22:23:53.0923 3864        avipbb - ok
22:23:54.0126 3864        BDA_Loader_220A (f01462daddcf46f00e84d295c5b8fc0b) C:\Windows\system32\Drivers\BDA_Loader_220A.sys
22:23:54.0189 3864        BDA_Loader_220A ( UnsignedFile.Multi.Generic ) - warning
22:23:54.0189 3864        BDA_Loader_220A - detected UnsignedFile.Multi.Generic (1)
22:23:54.0267 3864        Beep            (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
22:23:54.0376 3864        Beep - ok
22:23:54.0517 3864        blbdrive - ok
22:23:54.0579 3864        bowser          (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys
22:23:54.0642 3864        bowser - ok
22:23:54.0767 3864        BrFiltLo        (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
22:23:54.0986 3864        BrFiltLo - ok
22:23:55.0126 3864        BrFiltUp        (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
22:23:55.0204 3864        BrFiltUp - ok
22:23:55.0314 3864        Brserid        (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
22:23:55.0454 3864        Brserid - ok
22:23:55.0611 3864        BrSerWdm        (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
22:23:55.0767 3864        BrSerWdm - ok
22:23:55.0814 3864        BrUsbMdm        (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
22:23:55.0939 3864        BrUsbMdm - ok
22:23:55.0986 3864        BrUsbSer        (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
22:23:56.0064 3864        BrUsbSer - ok
22:23:56.0236 3864        BthEnum        (6d39c954799b63ba866910234cf7d726) C:\Windows\system32\DRIVERS\BthEnum.sys
22:23:56.0314 3864        BthEnum - ok
22:23:56.0392 3864        BTHMODEM        (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
22:23:56.0532 3864        BTHMODEM - ok
22:23:56.0689 3864        BthPan          (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys
22:23:56.0767 3864        BthPan - ok
22:23:56.0876 3864        BTHPORT        (4a74bbb2b6761789f42a6613479bdb1d) C:\Windows\system32\Drivers\BTHport.sys
22:23:57.0017 3864        BTHPORT - ok
22:23:57.0173 3864        BTHUSB          (1a407f9b707a06f55aa150f9aa072b09) C:\Windows\system32\Drivers\BTHUSB.sys
22:23:57.0251 3864        BTHUSB - ok
22:23:57.0345 3864        Cam5603D        (441373e054f3a42e6074e5a2a125a37a) C:\Windows\system32\Drivers\BisonCam.sys
22:23:57.0423 3864        Cam5603D - ok
22:23:57.0564 3864        cdfs            (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
22:23:57.0642 3864        cdfs - ok
22:23:57.0720 3864        cdrom          (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
22:23:57.0782 3864        cdrom - ok
22:23:57.0845 3864        circlass        (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys
22:23:57.0923 3864        circlass - ok
22:23:58.0064 3864        CLFS            (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
22:23:58.0079 3864        CLFS - ok
22:23:58.0189 3864        CmBatt          (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
22:23:58.0236 3864        CmBatt - ok
22:23:58.0392 3864        cmdide          (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys
22:23:58.0392 3864        cmdide - ok
22:23:58.0439 3864        Compbatt        (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
22:23:58.0454 3864        Compbatt - ok
22:23:58.0486 3864        crcdisk        (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys
22:23:58.0501 3864        crcdisk - ok
22:23:58.0548 3864        Crusoe          (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys
22:23:58.0642 3864        Crusoe - ok
22:23:58.0845 3864        CVirtA          (5c706c06c1279952d2cc1a609ca948bf) C:\Windows\system32\DRIVERS\CVirtA.sys
22:23:58.0876 3864        CVirtA - ok
22:23:59.0001 3864        DfsC            (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys
22:23:59.0079 3864        DfsC - ok
22:23:59.0298 3864        disk            (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
22:23:59.0314 3864        disk - ok
22:23:59.0392 3864        DNE            (2eddbb3ef1dd5a28cb07c149d36e7286) C:\Windows\system32\DRIVERS\dne2000.sys
22:23:59.0439 3864        DNE ( UnsignedFile.Multi.Generic ) - warning
22:23:59.0439 3864        DNE - detected UnsignedFile.Multi.Generic (1)
22:23:59.0626 3864        drmkaud        (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
22:23:59.0689 3864        drmkaud - ok
22:23:59.0798 3864        DslMNLwf        (e577b5c4a6be078e5445cdcfb65be7ab) C:\Windows\system32\DRIVERS\dslmnlwf.sys
22:23:59.0814 3864        DslMNLwf - ok
22:23:59.0970 3864        dsltestSp5      (c6b2e10cfe79169c72f0269087b9a603) C:\Windows\system32\Drivers\dsltestSp5.sys
22:23:59.0986 3864        dsltestSp5 - ok
22:24:00.0111 3864        DXGKrnl        (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
22:24:00.0173 3864        DXGKrnl - ok
22:24:00.0236 3864        E1G60          (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys
22:24:00.0314 3864        E1G60 - ok
22:24:00.0470 3864        Ecache          (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
22:24:00.0501 3864        Ecache - ok
22:24:00.0579 3864        elxstor        (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys
22:24:00.0595 3864        elxstor - ok
22:24:00.0720 3864        exfat          (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
22:24:00.0814 3864        exfat - ok
22:24:00.0986 3864        fastfat        (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
22:24:01.0064 3864        fastfat - ok
22:24:01.0157 3864        fdc            (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys
22:24:01.0282 3864        fdc - ok
22:24:01.0439 3864        FileInfo        (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
22:24:01.0454 3864        FileInfo - ok
22:24:01.0501 3864        Filetrace      (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
22:24:01.0548 3864        Filetrace - ok
22:24:01.0611 3864        flpydisk        (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys
22:24:01.0673 3864        flpydisk - ok
22:24:01.0814 3864        FltMgr          (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
22:24:01.0829 3864        FltMgr - ok
22:24:01.0923 3864        Fs_Rec          (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
22:24:01.0954 3864        Fs_Rec - ok
22:24:02.0001 3864        gagp30kx        (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys
22:24:02.0017 3864        gagp30kx - ok
22:24:02.0157 3864        grmnusb        (d956358054e99e6ffac69cd87e893a89) C:\Windows\system32\drivers\grmnusb.sys
22:24:02.0204 3864        grmnusb - ok
22:24:02.0407 3864        HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
22:24:02.0486 3864        HdAudAddService - ok
22:24:02.0626 3864        HDAudBus        (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
22:24:02.0720 3864        HDAudBus - ok
22:24:02.0939 3864        HidBth          (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
22:24:03.0048 3864        HidBth - ok
22:24:03.0095 3864        HidIr          (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
22:24:03.0157 3864        HidIr - ok
22:24:03.0236 3864        HidUsb          (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
22:24:03.0282 3864        HidUsb - ok
22:24:03.0548 3864        HpCISSs        (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys
22:24:03.0564 3864        HpCISSs - ok
22:24:03.0642 3864        HTTP            (0eeeca26c8d4bde2a4664db058a81937) C:\Windows\system32\drivers\HTTP.sys
22:24:03.0751 3864        HTTP - ok
22:24:03.0892 3864        i2omp          (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys
22:24:03.0892 3864        i2omp - ok
22:24:03.0986 3864        i8042prt        (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
22:24:04.0048 3864        i8042prt - ok
22:24:04.0204 3864        iaStorV        (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys
22:24:04.0220 3864        iaStorV - ok
22:24:04.0282 3864        iirsp          (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
22:24:04.0282 3864        iirsp - ok
22:24:04.0423 3864        IntcAzAudAddService (c61b3b87f3856cef0c9f204028c6860d) C:\Windows\system32\drivers\RTKVHDA.sys
22:24:04.0517 3864        IntcAzAudAddService - ok
22:24:04.0689 3864        intelide        (97469037714070e45194ed318d636401) C:\Windows\system32\drivers\intelide.sys
22:24:04.0720 3864        intelide - ok
22:24:04.0782 3864        intelppm        (ce44cc04262f28216dd4341e9e36a16f) C:\Windows\system32\DRIVERS\intelppm.sys
22:24:04.0892 3864        intelppm - ok
22:24:04.0986 3864        IpFilterDriver  (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:24:05.0017 3864        IpFilterDriver - ok
22:24:05.0048 3864        IpInIp - ok
22:24:05.0173 3864        IPMIDRV        (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys
22:24:05.0251 3864        IPMIDRV - ok
22:24:05.0298 3864        IPNAT          (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
22:24:05.0329 3864        IPNAT - ok
22:24:05.0392 3864        IRENUM          (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
22:24:05.0407 3864        IRENUM - ok
22:24:05.0548 3864        isapnp          (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys
22:24:05.0564 3864        isapnp - ok
22:24:05.0642 3864        iScsiPrt        (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
22:24:05.0657 3864        iScsiPrt - ok
22:24:05.0704 3864        iteatapi        (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
22:24:05.0704 3864        iteatapi - ok
22:24:05.0751 3864        iteraid        (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
22:24:05.0767 3864        iteraid - ok
22:24:05.0829 3864        kbdclass        (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
22:24:05.0845 3864        kbdclass - ok
22:24:05.0986 3864        kbdhid          (d2600cb17b7408b4a83f231dc9a11ac3) C:\Windows\system32\drivers\kbdhid.sys
22:24:06.0064 3864        kbdhid - ok
22:24:06.0142 3864        KSecDD          (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
22:24:06.0189 3864        KSecDD - ok
22:24:06.0251 3864        lltdio          (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
22:24:06.0314 3864        lltdio - ok
22:24:06.0470 3864        LSI_FC          (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys
22:24:06.0486 3864        LSI_FC - ok
22:24:06.0517 3864        LSI_SAS        (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys
22:24:06.0532 3864        LSI_SAS - ok
22:24:06.0595 3864        LSI_SCSI        (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys
22:24:06.0611 3864        LSI_SCSI - ok
22:24:06.0673 3864        luafv          (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
22:24:06.0720 3864        luafv - ok
22:24:06.0892 3864        MDC8021X        (8fee53c104223973ed9919936d9cd156) C:\Windows\system32\DRIVERS\mdc8021x.sys
22:24:06.0907 3864        MDC8021X ( UnsignedFile.Multi.Generic ) - warning
22:24:06.0907 3864        MDC8021X - detected UnsignedFile.Multi.Generic (1)
22:24:06.0986 3864        megasas        (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys
22:24:07.0001 3864        megasas - ok
22:24:07.0064 3864        MGHwCtrl        (25a4177b8abf458691138f0c9684e70f) C:\Windows\system32\drivers\MGHwCtrl.sys
22:24:07.0079 3864        MGHwCtrl ( UnsignedFile.Multi.Generic ) - warning
22:24:07.0079 3864        MGHwCtrl - detected UnsignedFile.Multi.Generic (1)
22:24:07.0251 3864        Modem          (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
22:24:07.0329 3864        Modem - ok
22:24:07.0423 3864        monitor        (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
22:24:07.0501 3864        monitor - ok
22:24:07.0595 3864        mouclass        (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
22:24:07.0611 3864        mouclass - ok
22:24:07.0736 3864        mouhid          (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
22:24:07.0814 3864        mouhid - ok
22:24:07.0876 3864        MountMgr        (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
22:24:07.0907 3864        MountMgr - ok
22:24:07.0986 3864        mpio            (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys
22:24:08.0017 3864        mpio - ok
22:24:08.0142 3864        mpsdrv          (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
22:24:08.0204 3864        mpsdrv - ok
22:24:08.0267 3864        Mraid35x        (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
22:24:08.0298 3864        Mraid35x - ok
22:24:08.0361 3864        MRxDAV          (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
22:24:08.0439 3864        MRxDAV - ok
22:24:08.0798 3864        mrxsmb          (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:24:08.0861 3864        mrxsmb - ok
22:24:08.0954 3864        mrxsmb10        (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:24:09.0017 3864        mrxsmb10 - ok
22:24:09.0111 3864        mrxsmb20        (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:24:09.0157 3864        mrxsmb20 - ok
22:24:09.0267 3864        msahci          (742aed7939e734c36b7e8d6228ce26b7) C:\Windows\system32\drivers\msahci.sys
22:24:09.0282 3864        msahci - ok
22:24:09.0329 3864        msdsm          (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys
22:24:09.0361 3864        msdsm - ok
22:24:09.0486 3864        Msfs            (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
22:24:09.0548 3864        Msfs - ok
22:24:09.0689 3864        msisadrv        (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
22:24:09.0720 3864        msisadrv - ok
22:24:09.0845 3864        MSKSSRV        (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
22:24:09.0939 3864        MSKSSRV - ok
22:24:10.0017 3864        MSPCLOCK        (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
22:24:10.0095 3864        MSPCLOCK - ok
22:24:10.0236 3864        MSPQM          (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
22:24:10.0314 3864        MSPQM - ok
22:24:10.0407 3864        MsRPC          (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
22:24:10.0439 3864        MsRPC - ok
22:24:10.0532 3864        mssmbios        (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
22:24:10.0548 3864        mssmbios - ok
22:24:10.0689 3864        MSTEE          (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
22:24:10.0736 3864        MSTEE - ok
22:24:10.0845 3864        Mup            (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
22:24:10.0861 3864        Mup - ok
22:24:10.0954 3864        NativeWifiP    (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
22:24:10.0986 3864        NativeWifiP - ok
22:24:11.0142 3864        NDIS            (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
22:24:11.0204 3864        NDIS - ok
22:24:11.0282 3864        NdisTapi        (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
22:24:11.0361 3864        NdisTapi - ok
22:24:11.0439 3864        Ndisuio        (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
22:24:11.0517 3864        Ndisuio - ok
22:24:11.0657 3864        NdisWan        (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
22:24:11.0736 3864        NdisWan - ok
22:24:11.0814 3864        NDProxy        (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
22:24:11.0861 3864        NDProxy - ok
22:24:11.0970 3864        NetBIOS        (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
22:24:12.0017 3864        NetBIOS - ok
22:24:12.0157 3864        netbt          (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
22:24:12.0204 3864        netbt - ok
22:24:12.0314 3864        nfrd960        (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
22:24:12.0329 3864        nfrd960 - ok
22:24:12.0423 3864        Npfs            (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
22:24:12.0470 3864        Npfs - ok
22:24:12.0579 3864        nsiproxy        (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
22:24:12.0626 3864        nsiproxy - ok
22:24:12.0767 3864        Ntfs            (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
22:24:12.0829 3864        Ntfs - ok
22:24:12.0986 3864        ntrigdigi      (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
22:24:13.0111 3864        ntrigdigi - ok
22:24:13.0157 3864        Null            (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
22:24:13.0189 3864        Null - ok
22:24:13.0220 3864        nvraid          (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys
22:24:13.0236 3864        nvraid - ok
22:24:13.0267 3864        nvstor          (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys
22:24:13.0282 3864        nvstor - ok
22:24:13.0329 3864        nv_agp          (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys
22:24:13.0345 3864        nv_agp - ok
22:24:13.0439 3864        NwlnkFlt - ok
22:24:13.0470 3864        NwlnkFwd - ok
22:24:13.0532 3864        O2MDRDR        (a874f4e22d116bf5701db6dd8bcb1d27) C:\Windows\system32\DRIVERS\o2media.sys
22:24:13.0579 3864        O2MDRDR - ok
22:24:13.0626 3864        O2SDRDR        (55153f3f852c4bc0e050a65f5d914c01) C:\Windows\system32\DRIVERS\o2sd.sys
22:24:13.0642 3864        O2SDRDR - ok
22:24:13.0720 3864        ohci1394        (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys
22:24:13.0751 3864        ohci1394 - ok
22:24:13.0986 3864        Parport        (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
22:24:14.0032 3864        Parport - ok
22:24:14.0111 3864        partmgr        (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
22:24:14.0111 3864        partmgr - ok
22:24:14.0157 3864        Parvdm          (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
22:24:14.0204 3864        Parvdm - ok
22:24:14.0282 3864        pci            (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
22:24:14.0298 3864        pci - ok
22:24:14.0439 3864        pciide          (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys
22:24:14.0454 3864        pciide - ok
22:24:14.0532 3864        pcmcia          (3bb2244f343b610c29c98035504c9b75) C:\Windows\system32\DRIVERS\pcmcia.sys
22:24:14.0548 3864        pcmcia - ok
22:24:14.0657 3864        PEAUTH          (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
22:24:14.0798 3864        PEAUTH - ok
22:24:15.0017 3864        PptpMiniport    (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
22:24:15.0032 3864        PptpMiniport - ok
22:24:15.0095 3864        Processor      (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys
22:24:15.0157 3864        Processor - ok
22:24:15.0282 3864        PSched          (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
22:24:15.0314 3864        PSched - ok
22:24:15.0454 3864        PxHelp20        (d86b4a68565e444d76457f14172c875a) C:\Windows\system32\Drivers\PxHelp20.sys
22:24:15.0454 3864        PxHelp20 - ok
22:24:15.0548 3864        ql2300          (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys
22:24:15.0595 3864        ql2300 - ok
22:24:15.0720 3864        ql40xx          (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
22:24:15.0736 3864        ql40xx - ok
22:24:15.0798 3864        QWAVEdrv        (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
22:24:15.0829 3864        QWAVEdrv - ok
22:24:15.0970 3864        R300            (e52b7a5010011c29063684cac1a6bbf0) C:\Windows\system32\DRIVERS\atikmdag.sys
22:24:16.0189 3864        R300 - ok
22:24:16.0314 3864        RasAcd          (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
22:24:16.0376 3864        RasAcd - ok
22:24:16.0439 3864        Rasl2tp        (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:24:16.0486 3864        Rasl2tp - ok
22:24:16.0642 3864        RasPppoe        (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
22:24:16.0704 3864        RasPppoe - ok
22:24:16.0798 3864        RasSstp        (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
22:24:16.0829 3864        RasSstp - ok
22:24:16.0907 3864        rdbss          (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
22:24:16.0939 3864        rdbss - ok
22:24:17.0064 3864        RDPCDD          (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:24:17.0142 3864        RDPCDD - ok
22:24:17.0236 3864        rdpdr          (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys
22:24:17.0361 3864        rdpdr - ok
22:24:17.0392 3864        RDPENCDD        (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
22:24:17.0423 3864        RDPENCDD - ok
22:24:17.0501 3864        RDPWD          (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
22:24:17.0548 3864        RDPWD - ok
22:24:17.0720 3864        RFCOMM          (6482707f9f4da0ecbab43b2e0398a101) C:\Windows\system32\DRIVERS\rfcomm.sys
22:24:17.0782 3864        RFCOMM - ok
22:24:17.0876 3864        rspndr          (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
22:24:17.0907 3864        rspndr - ok
22:24:18.0064 3864        rt61x86        (25c699c801685c69557c60f6da01d90a) C:\Windows\system32\DRIVERS\netr61.sys
22:24:18.0126 3864        rt61x86 - ok
22:24:18.0314 3864        SANDRA          (230fd3749904ca045ea5ec0aa14006e9) C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2012.SP1\WNt500x86\Sandra.sys
22:24:18.0329 3864        SANDRA - ok
22:24:18.0501 3864        sbp2port        (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
22:24:18.0517 3864        sbp2port - ok
22:24:18.0595 3864        sdbus          (4339a2585708c7d9b0c0ce5aad3dd6ff) C:\Windows\system32\DRIVERS\sdbus.sys
22:24:18.0689 3864        sdbus - ok
22:24:18.0751 3864        secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
22:24:18.0861 3864        secdrv - ok
22:24:19.0017 3864        Serenum        (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
22:24:19.0126 3864        Serenum - ok
22:24:19.0173 3864        Serial          (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
22:24:19.0267 3864        Serial - ok
22:24:19.0329 3864        sermouse        (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
22:24:19.0376 3864        sermouse - ok
22:24:19.0532 3864        sffdisk        (103b79418da647736ee95645f305f68a) C:\Windows\system32\drivers\sffdisk.sys
22:24:19.0657 3864        sffdisk - ok
22:24:19.0704 3864        sffp_mmc        (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys
22:24:19.0751 3864        sffp_mmc - ok
22:24:19.0798 3864        sffp_sd        (9cfa05fcfcb7124e69cfc812b72f9614) C:\Windows\system32\drivers\sffp_sd.sys
22:24:19.0845 3864        sffp_sd - ok
22:24:19.0907 3864        sfloppy        (c33bfbd6e9e41fcd9ffef9729e9faed6) C:\Windows\system32\DRIVERS\sfloppy.sys
22:24:19.0939 3864        sfloppy - ok
22:24:20.0079 3864        sisagp          (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys
22:24:20.0095 3864        sisagp - ok
22:24:20.0142 3864        SiSRaid2        (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys
22:24:20.0157 3864        SiSRaid2 - ok
22:24:20.0189 3864        SiSRaid4        (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys
22:24:20.0204 3864        SiSRaid4 - ok
22:24:20.0298 3864        Smb            (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
22:24:20.0314 3864        Smb - ok
22:24:20.0392 3864        spldr          (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
22:24:20.0407 3864        spldr - ok
22:24:20.0579 3864        srv            (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys
22:24:20.0611 3864        srv - ok
22:24:20.0704 3864        srv2            (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys
22:24:20.0751 3864        srv2 - ok
22:24:20.0892 3864        srvnet          (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys
22:24:20.0907 3864        srvnet - ok
22:24:21.0001 3864        ssmdrv          (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
22:24:21.0001 3864        ssmdrv - ok
22:24:21.0095 3864        swenum          (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
22:24:21.0111 3864        swenum - ok
22:24:21.0251 3864        Symc8xx        (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
22:24:21.0251 3864        Symc8xx - ok
22:24:21.0314 3864        Sym_hi          (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
22:24:21.0314 3864        Sym_hi - ok
22:24:21.0361 3864        Sym_u3          (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
22:24:21.0376 3864        Sym_u3 - ok
22:24:21.0517 3864        Tcpip          (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys
22:24:21.0642 3864        Tcpip - ok
22:24:21.0782 3864        Tcpip6          (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys
22:24:21.0923 3864        Tcpip6 - ok
22:24:22.0017 3864        tcpipreg        (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
22:24:22.0126 3864        tcpipreg - ok
22:24:22.0267 3864        TDPIPE          (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
22:24:22.0329 3864        TDPIPE - ok
22:24:22.0407 3864        TDTCP          (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
22:24:22.0454 3864        TDTCP - ok
22:24:22.0532 3864        tdx            (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
22:24:22.0564 3864        tdx - ok
22:24:22.0626 3864        TermDD          (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
22:24:22.0642 3864        TermDD - ok
22:24:22.0829 3864        tosrfbd        (ce378f952a16fbfe355126d90d8f42e8) C:\Windows\system32\DRIVERS\tosrfbd.sys
22:24:22.0876 3864        tosrfbd - ok
22:24:22.0939 3864        Tosrfcom        (5ba1ca3b3cddb1ddc67df473f05d1ec2) C:\Windows\system32\drivers\Tosrfcom.sys
22:24:22.0970 3864        Tosrfcom - ok
22:24:23.0032 3864        Tosrfhid        (28099a4e52148319afa685d93a2244d0) C:\Windows\system32\DRIVERS\Tosrfhid.sys
22:24:23.0095 3864        Tosrfhid - ok
22:24:23.0236 3864        Tosrfusb        (20cc46c5d3326122e1a0a8c9dad00e0d) C:\Windows\system32\DRIVERS\tosrfusb.sys
22:24:23.0314 3864        Tosrfusb - ok
22:24:23.0407 3864        tssecsrv        (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:24:23.0486 3864        tssecsrv - ok
22:24:23.0564 3864        tunmp          (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
22:24:23.0626 3864        tunmp - ok
22:24:23.0767 3864        tunnel          (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
22:24:23.0798 3864        tunnel - ok
22:24:23.0876 3864        uagp35          (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys
22:24:23.0892 3864        uagp35 - ok
22:24:24.0001 3864        udfs            (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
22:24:24.0095 3864        udfs - ok
22:24:24.0251 3864        uliagpkx        (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys
22:24:24.0282 3864        uliagpkx - ok
22:24:24.0329 3864        uliahci        (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys
22:24:24.0361 3864        uliahci - ok
22:24:24.0423 3864        UlSata          (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
22:24:24.0439 3864        UlSata - ok
22:24:24.0486 3864        ulsata2        (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
22:24:24.0501 3864        ulsata2 - ok
22:24:24.0595 3864        umbus          (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
22:24:24.0626 3864        umbus - ok
22:24:24.0767 3864        usbccgp        (8bd3ae150d97ba4e633c6c5c51b41ae1) C:\Windows\system32\drivers\usbccgp.sys
22:24:24.0861 3864        usbccgp - ok
22:24:24.0939 3864        usbcir          (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
22:24:25.0001 3864        usbcir - ok
22:24:25.0095 3864        usbehci        (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
22:24:25.0111 3864        usbehci - ok
22:24:25.0204 3864        usbhub          (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
22:24:25.0251 3864        usbhub - ok
22:24:25.0329 3864        usbohci        (ce697fee0d479290d89bec80dfe793b7) C:\Windows\system32\DRIVERS\usbohci.sys
22:24:25.0361 3864        usbohci - ok
22:24:25.0423 3864        usbprint        (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
22:24:25.0486 3864        usbprint - ok
22:24:25.0611 3864        USBSTOR        (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:24:25.0642 3864        USBSTOR - ok
22:24:25.0720 3864        usbuhci        (325dbbacb8a36af9988ccf40eac228cc) C:\Windows\system32\DRIVERS\usbuhci.sys
22:24:25.0767 3864        usbuhci - ok
22:24:25.0876 3864        vga            (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys
22:24:25.0923 3864        vga - ok
22:24:25.0986 3864        VgaSave        (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
22:24:26.0032 3864        VgaSave - ok
22:24:26.0157 3864        viaagp          (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys
22:24:26.0173 3864        viaagp - ok
22:24:26.0236 3864        ViaC7          (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys
22:24:26.0345 3864        ViaC7 - ok
22:24:26.0407 3864        viaide          (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys
22:24:26.0423 3864        viaide - ok
22:24:26.0486 3864        volmgr          (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
22:24:26.0501 3864        volmgr - ok
22:24:26.0642 3864        volmgrx        (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
22:24:26.0673 3864        volmgrx - ok
22:24:26.0767 3864        volsnap        (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
22:24:26.0782 3864        volsnap - ok
22:24:26.0892 3864        vsmraid        (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys
22:24:26.0907 3864        vsmraid - ok
22:24:27.0079 3864        WacomPen        (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
22:24:27.0220 3864        WacomPen - ok
22:24:27.0282 3864        Wanarp          (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
22:24:27.0314 3864        Wanarp - ok
22:24:27.0329 3864        Wanarpv6        (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
22:24:27.0345 3864        Wanarpv6 - ok
22:24:27.0423 3864        wanatw          (0a716c08cb13c3a8f4f51e882dbf7416) C:\Windows\system32\DRIVERS\wanatw4.sys
22:24:27.0470 3864        wanatw - ok
22:24:27.0611 3864        Wd              (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys
22:24:27.0626 3864        Wd - ok
22:24:27.0689 3864        Wdf01000        (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
22:24:27.0720 3864        Wdf01000 - ok
22:24:27.0892 3864        WmiAcpi        (701a9f884a294327e9141d73746ee279) C:\Windows\system32\drivers\wmiacpi.sys
22:24:27.0970 3864        WmiAcpi - ok
22:24:28.0142 3864        WpdUsb          (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
22:24:28.0204 3864        WpdUsb - ok
22:24:28.0267 3864        ws2ifsl        (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
22:24:28.0314 3864        ws2ifsl - ok
22:24:28.0423 3864        WUDFRd          (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:24:28.0470 3864        WUDFRd - ok
22:24:28.0579 3864        MBR (0x1B8)    (95a73b4cdf11ada3a91d4f313293dfd6) \Device\Harddisk0\DR0
22:24:28.0907 3864        \Device\Harddisk0\DR0 - ok
22:24:28.0923 3864        Boot (0x1200)  (560e7be9b30f7e4619c1eef87454266b) \Device\Harddisk0\DR0\Partition0
22:24:28.0923 3864        \Device\Harddisk0\DR0\Partition0 - ok
22:24:28.0923 3864        ============================================================
22:24:28.0923 3864        Scan finished
22:24:28.0923 3864        ============================================================
22:24:28.0954 1472        Detected object count: 5
22:24:28.0954 1472        Actual detected object count: 5
22:24:59.0517 1472        athrusb ( UnsignedFile.Multi.Generic ) - skipped by user
22:24:59.0517 1472        athrusb ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:24:59.0532 1472        BDA_Loader_220A ( UnsignedFile.Multi.Generic ) - skipped by user
22:24:59.0532 1472        BDA_Loader_220A ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:24:59.0532 1472        DNE ( UnsignedFile.Multi.Generic ) - skipped by user
22:24:59.0532 1472        DNE ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:24:59.0548 1472        MDC8021X ( UnsignedFile.Multi.Generic ) - skipped by user
22:24:59.0548 1472        MDC8021X ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:24:59.0548 1472        MGHwCtrl ( UnsignedFile.Multi.Generic ) - skipped by user
22:24:59.0548 1472        MGHwCtrl ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 08.01.2012 22:31

Dann bitte jetzt CF ausführen:

ComboFix

Ein Leitfaden und Tutorium zur Nutzung von ComboFix
  • Schliesse alle Programme, vor allem dein Antivirenprogramm und andere Hintergrundwächter sowie deinen Internetbrowser.
  • Starte cofi.exe von deinem Desktop aus, bestätige die Warnmeldungen, führe die Updates durch (falls vorgeschlagen), installiere die Wiederherstellungskonsole (falls vorgeschlagen) und lass dein System durchsuchen.
    Vermeide es auch während Combofix läuft die Maus und Tastatur zu benutzen.
  • Im Anschluss öffnet sich automatisch eine combofix.txt, diesen Inhalt bitte kopieren ([Strg]a, [Strg]c) und in deinen Beitrag einfügen ([Strg]v). Die Datei findest du außerdem unter: C:\ComboFix.txt.
Wichtiger Hinweis:
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!

Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren.

Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie

Zitat:

Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
startest du Windows dann manuell neu und die Fehlermeldungen sollten nicht mehr auftauchen.

dieba 08.01.2012 23:23

Hallo Arne,
musste erst noch mal neu booten (wegen Fehlermeldung) und war noch irritiert, weil nach Anklicken von "Herunterfahren..." erst die Auswahl "Updates installieren und ..." erschien, habe dann nur "Neustart" gewählt. Augenscheinlich hat MS gerade updates bereitgestellt.
Hier das Ergebnis von Combofix:

Code:

ComboFix 12-01-07.03 - christa 08.01.2012  22:41:58.1.1 - x86
Microsoft® Windows Vista™ Home Basic  6.0.6002.2.1252.49.1031.18.895.321 [GMT 1:00]
ausgeführt von:: c:\users\christa\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\christa\AppData\Roaming\mIRC\logs\status.log
c:\windows\system32\drivers\etc\hosts.ics
.
.
(((((((((((((((((((((((  Dateien erstellt von 2011-12-08 bis 2012-01-08  ))))))))))))))))))))))))))))))
.
.
2012-01-08 13:21 . 2012-01-08 13:21        --------        d-----w-        C:\_OTL
2012-01-07 10:16 . 2012-01-07 10:16        --------        d-----w-        c:\program files\ESET
2012-01-06 09:32 . 2011-11-21 10:47        6823496        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{98BC21DA-1D0E-4936-9383-B6B6033225D7}\mpengine.dll
2012-01-04 20:10 . 2012-01-04 20:10        --------        d-----w-        c:\program files\7-Zip
2012-01-04 17:10 . 2012-01-04 17:11        --------        d-----w-        c:\users\christa\!!Systemänderungen
2012-01-04 11:33 . 2012-01-04 11:33        626688        ----a-w-        c:\program files\Mozilla Firefox\msvcr80.dll
2012-01-04 11:33 . 2012-01-04 11:33        548864        ----a-w-        c:\program files\Mozilla Firefox\msvcp80.dll
2012-01-04 11:33 . 2012-01-04 11:33        479232        ----a-w-        c:\program files\Mozilla Firefox\msvcm80.dll
2012-01-04 11:33 . 2012-01-04 11:33        43992        ----a-w-        c:\program files\Mozilla Firefox\mozutils.dll
2012-01-03 19:13 . 2012-01-03 19:13        --------        d-----w-        c:\users\christa\AppData\Roaming\JAM Software
2012-01-03 19:13 . 2012-01-03 19:13        --------        d-----w-        c:\program files\JAM Software
2012-01-02 20:41 . 2012-01-02 20:41        --------        d-----w-        c:\program files\Belarc
2012-01-01 14:51 . 2008-10-27 09:04        514384        ----a-w-        c:\windows\system32\XAudio2_3.dll
2012-01-01 14:31 . 2012-01-01 14:31        --------        d-----w-        c:\program files\SiSoftware
2011-12-22 19:50 . 2011-12-22 19:50        --------        d-----w-        c:\program files\MSECache
2011-12-16 13:14 . 2011-11-03 22:31        2382848        ----a-w-        c:\windows\system32\mshtml.tlb
2011-12-15 18:07 . 2011-10-27 08:01        3602816        ----a-w-        c:\windows\system32\ntkrnlpa.exe
2011-12-15 18:07 . 2011-10-27 08:01        3550080        ----a-w-        c:\windows\system32\ntoskrnl.exe
2011-12-15 18:07 . 2011-10-14 16:02        429056        ----a-w-        c:\windows\system32\EncDec.dll
2011-12-15 18:07 . 2011-11-23 13:37        2043904        ----a-w-        c:\windows\system32\win32k.sys
2011-12-15 18:07 . 2011-11-08 12:10        2409784        ----a-w-        c:\program files\Windows Mail\OESpamFilter.dat
2011-12-15 18:07 . 2011-10-25 15:56        49152        ----a-w-        c:\windows\system32\csrsrv.dll
2011-12-15 18:07 . 2011-11-08 14:42        2048        ----a-w-        c:\windows\system32\tzres.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-25 18:33 . 2011-05-21 08:55        414368        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-10 14:24 . 2011-11-29 23:06        20464        ----a-w-        c:\windows\system32\drivers\mbam.sys
2012-01-04 11:33 . 2011-04-03 17:34        121816        ----a-w-        c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"RtHDVCpl"="RtHDVCpl.exe" [2006-12-29 4317184]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-30 281768]
.
c:\users\christa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled
DSL-Manager.lnk - c:\program files\DSL-Manager\DslMgr.exe [2007-11-15 1085440]
.
c:\users\christa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled\~Disabled
DSL-Manager.lnk - c:\program files\DSL-Manager\DslMgr.exe [2007-11-15 1085440]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled\~Disabled
PDFCreator.lnk - c:\program files\PDFCreator\PDFCreator.exe [2010-6-7 3084288]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
DSL-Manager.lnk - c:\program files\DSL-Manager\DslMgr.exe [2007-11-15 1085440]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^phase-6 Reminder.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\phase-6 Reminder.lnk
backup=c:\windows\pss\phase-6 Reminder.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
REM [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
REM [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-21 23:57        35760        ----a-w-        c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]
2011-12-24 16:50        981680        ----a-w-        c:\program files\Malwarebytes' Anti-Malware\mbam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-04-05 21:31        39408        ----a-w-        c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=REM "c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe"
"swg"=REM c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - 37632283
*Deregistered* - 37632283
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork        REG_MULTI_SZ          PLA DPS BFE mpssvc
bthsvcs        REG_MULTI_SZ          BthServ
LocalServiceAndNoImpersonation        REG_MULTI_SZ          FontCache
.
Inhalt des "geplante Tasks" Ordners
.
2012-01-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 13:21]
.
2012-01-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-07 19:07]
.
2012-01-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-07 19:07]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.juelich.de/
IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Öffnen mit WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\christa\AppData\Roaming\Mozilla\Firefox\Profiles\8p6t23gq.default\
FF - prefs.js: browser.search.selectedEngine - Google Deutschland
FF - prefs.js: browser.startup.homepage - hxxp://www.juelich.de/stabue/
FF - user.js: yahoo.homepage.dontask - true
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
MSConfigStartUp-Adobe ARM - c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
HKLM_ActiveSetup-ccc-core-static - msiexec
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2012-01-08 22:53
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
  00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Zeit der Fertigstellung: 2012-01-08  23:01:29
ComboFix-quarantined-files.txt  2012-01-08 22:01
.
Vor Suchlauf: 10 Verzeichnis(se), 54.135.246.848 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 54.057.295.872 Bytes frei
.
- - End Of File - - 5597650A0972F0CC23F3B5B299F07E74


cosinus 09.01.2012 11:07

Zitat:

c:\users\christa\!!Systemänderungen
Was ist das für ein Ordner?

dieba 09.01.2012 11:42

Hallo Arne,
bin nicht mehr ganz so jung (68) und merkfähig, führe deshalb bei solchen Sachen möglichst Buch. !!Systemänderungen ("!!" wegen schneller Auffindbarkeit) enthält momentan genau eine Datei NachCrash20120101.txt, Inhalt siehe unten. Was mich irritiert, ist, dass bis gerade (mehr als 10 min nach logon) der Rechner mit plattenzugriff so blockiert war, dass Eingabe hier für mehrere Sekunden blockiert/verzögert wurde, starten des Task-Managers fast 1 min brauchte und das anschließende starten des Resourcenmonitors daraus noch viel länger, während dessen die Darstellung im Taskmonitor einfror. Dachte schon, das System wäre eingefroren, bis es dann weiterging. Jetzt läuft alles halbwegs passabel.

Code:

Dienste geändert:
        superfetch                                        aut. ->        deakt.
        Windows Verwaltungsinstr.                aut. ->        manuell

autoruns Änderungen (deaktiviert):
        Logon                CNAP2 Launcher, MGSysCtrl        [HKLM\SOFTWARE\Microsoft\Windows\CurrentVerion\Run]
                        ~Disabled (PDFCreator)                [C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup]
                        ~Disabled (DSL-Manager)                [C:\Users\christa\AppData\Roaming\Microsoft\Windows\Start Menu
                                                                        \Programs\Startup\AutorunsDisabled]
        Services        WMPNetworkSvc                        [HKLM\System\CurrentControlSet\Services]
                        SandraAgentSrv                        [HKLM\System\CurrentControlSet\Services]


dieba 09.01.2012 12:05

Nachtrag:
habe gerade mal in die Ereignisanzeige geschaut (1.Mal!). Zeigt nach Starten "kritisch" und 2x"Fehler" an.
Code:

Ereignis 100
Windows wurde gestartet:
    Startdauer                :                :        162473ms
    Beeinträchtigung                :        false
    Vorfallzeit (UTC)        :        09.01.2012 10:09:48
Ereignis 400:
Informationen zum Systemleistungs-Überwachungsereignis:
    Szenario                :        Systemreaktionsverhalten
    Analyseergebnis                :        Die Analyse war erfolgreich, und es wurden Fehlerursachen gefunden.
    Vorfallzeit (UTC)        :        09.01.2012 10:20:23
Ereignis 400:
Dieser Prozess führt zu viele Datenträgeraktivitäten aus beeinflusst die Leistung von Windows:
    Dateiname                :        \Windows\System32\msiexec.exe
    Anzeigename                :        Windows® Installer
    Version                :        4.5.6002.18005 (lh_sp2rtm.090410-1830)
    Threadzeit                :        198ms
    Blockierte Zeit                :        54ms
    Vorfallzeit (UTC)        :        09.01.2012 10:20:23

und noch zwei nachfolgende "Warnings":
Dieser Prozess führt zu viele Datenträgeraktivitäten aus beeinflusst die Leistung von Windows:
    Dateiname                :        \Device\HarddiskVolume1\Windows\System32\SearchIndexer.exe
    Anzeigename                :        Microsoft Windows Search-Indexerstellung
    Version                :        7.00.6002.18005 (lh_sp2rtm.090410-1830)
    Threadzeit                :        198ms
    Blockierte Zeit                :        30ms
    Vorfallzeit (UTC)        :        09.01.2012 10:20:23
Dieser Prozess führt zu viele Datenträgeraktivitäten aus beeinflusst die Leistung von Windows:
    Dateiname                :        \Device\HarddiskVolume1\Program Files\Avira\AntiVir Desktop\avguard.exe
    Anzeigename                :        Antivirus On-Access Service
    Version                :        10.00.01.59
    Threadzeit                :        198ms
    Blockierte Zeit                :        25ms
    Vorfallzeit (UTC)        :        09.01.2012 10:20:23


cosinus 09.01.2012 15:33

Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten.
GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus - die Online-Abfrage durch OSAM bitte überspringen.
Bei OSAM bitte darauf auch achten, dass Du das Log auch als *.log und nicht *.html oder so abspeicherst.

Hinweis: Zum Entpacken von OSAM bitte WinRAR oder 7zip verwenden! Stell auch unbedingt den Virenscanner ab, besonders der Scanner von McAfee meldet oft einen Fehalarm in OSAM!

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
  • Starte die aswMBR.exe - (aswMBR.exe Anleitung)
    Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten".
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen )
    Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS-Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort.

Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung

Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none).


dieba 09.01.2012 21:49

Guten Abend, Arne,

auf zum nächsten Schritt - scheint ja was hartnäckigeres zu sein. Zwischendurch schon mal vielen Dank für die Bemühungen!

GMER Scan:
Code:

GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-01-09 21:02:19
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_MK1234GAX rev.AC001A
Running: 3c5dcupk.exe; Driver: C:\Users\christa\AppData\Local\Temp\ugloypob.sys


---- System - GMER 1.0.15 ----

SSDT            8A27C076                                                                                        ZwCreateSection
SSDT            8A27C07B                                                                                        ZwSetContextThread
SSDT            8A27C017                                                                                        ZwTerminateProcess

---- Kernel code sections - GMER 1.0.15 ----

.text          ntkrnlpa.exe!KeSetEvent + 215                                                                    81EB2998 4 Bytes  [76, C0, 27, 8A]
.text          ntkrnlpa.exe!KeSetEvent + 56D                                                                    81EB2CF0 4 Bytes  [7B, C0, 27, 8A]
.text          ntkrnlpa.exe!KeSetEvent + 621                                                                    81EB2DA4 4 Bytes  [17, C0, 27, 8A] {POP SS; SHL BYTE [EDI], 0x8a}

---- User IAT/EAT - GMER 1.0.15 ----

IAT            C:\Windows\Explorer.EXE[1980] @ C:\Windows\system32\ole32.dll [msvcrt.dll!free]                  [7226F3FB] C:\Windows\AppPatch\AcSpecfc.DLL (Windows Compatibility DLL/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice  \FileSystem\fastfat \Fat                                                                        fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg            HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0013d382bfb8                     
Reg            HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0013d382bfb8 (not active ControlSet) 

---- EOF - GMER 1.0.15 ----

und OSAM Scan:
Code:

Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 21:27:52 on 09.01.2012

OS: Windows Vista Home Basic Edition Service Pack 2 (Build 6002), 32-bit
Default Browser: Mozilla Corporation Firefox 9.0.1

Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures

Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries


[Common]
-----( %SystemRoot%\Tasks )-----
"AppleSoftwareUpdate.job" - "Apple Computer, Inc." - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"GoogleUpdateTaskMachineCore.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"GoogleUpdateTaskMachineUA.job" - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe

[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"bdeadmin.cpl" - "Borland Software Corporation" - C:\Windows\system32\bdeadmin.cpl
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
"ISUSPM.cpl" - "Macrovision Corporation" - C:\Windows\system32\ISUSPM.cpl
"LocalCOM.cpl" - "TOSHIBA CORPORATION" - C:\Windows\system32\LocalCOM.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"Nero BurnRights" - "Nero AG" - C:\Program Files\Nero\Nero 7\Nero Toolkit\NeroBurnRights.cpl
"QuickTime" - "Apple Computer, Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl

[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"AEGIS Protocol (IEEE 802.1x) v2.3.1.10" (MDC8021X) - "Meetinghouse Data Communications" - C:\Windows\System32\DRIVERS\mdc8021x.sys
"Atheros Wireless LAN USB device driver" (athrusb) - "Atheros Communications, Inc." - C:\Windows\System32\DRIVERS\athrusb.sys
"avgio" (avgio) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avgio.sys
"avgntflt" (avgntflt) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avgntflt.sys
"avipbb" (avipbb) - "Avira GmbH" - C:\Windows\System32\DRIVERS\avipbb.sys
"catchme" (catchme) - ? - C:\Users\christa\AppData\Local\Temp\catchme.sys  (File not found)
"Digital-TV Receiver Firmware Loader 6.7.10.0" (BDA_Loader_220A) - "WideView Technology Inc." - C:\Windows\System32\Drivers\BDA_Loader_220A.sys
"dsltestSp5 NDIS Protocol Driver" (dsltestSp5) - "Printing Communications Assoc., Inc. (PCAUSA)" - C:\Windows\System32\Drivers\dsltestSp5.sys
"IP in IP Tunnel Driver" (IpInIp) - ? - C:\Windows\System32\DRIVERS\ipinip.sys  (File not found)
"IPX Traffic Filter Driver" (NwlnkFlt) - ? - C:\Windows\System32\DRIVERS\nwlnkflt.sys  (File not found)
"IPX Traffic Forwarder Driver" (NwlnkFwd) - ? - C:\Windows\System32\DRIVERS\nwlnkfwd.sys  (File not found)
"MGHwCtrl" (MGHwCtrl) - "Windows (R) 2000 DDK provider" - C:\Windows\system32\drivers\MGHwCtrl.sys
"PxHelp20" (PxHelp20) - "Sonic Solutions" - C:\Windows\System32\Drivers\PxHelp20.sys
"SANDRA" (SANDRA) - "SiSoftware" - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2012.SP1\WNt500x86\Sandra.sys
"ssmdrv" (ssmdrv) - "Avira GmbH" - C:\Windows\System32\DRIVERS\ssmdrv.sys

[Explorer]
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
AutorunsDisabled "AutorunsDisabled" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\Software\Classes\Protocols\Filter )-----
{807553E5-5146-11D5-A672-00B0D022E945} "text/xml" - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
-----( HKLM\Software\Classes\Protocols\Handler )-----
{32505114-5902-49B2-880A-1F7738E5A384} "Data Page Plugable Protocal mso-offdap11 Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
{6318E0AB-2E93-11D1-B8ED-00608CC9A71F} "VoilaXctl Class" - "Belarc, Inc." - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? -  (File not found | COM-object registry key not found)
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? -  (File not found | COM-object registry key not found)
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? -  (File not found | COM-object registry key not found)
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? -  (File not found | COM-object registry key not found)
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? -  (File not found | COM-object registry key not found)
{00020d75-0000-0000-c000-000000000046} "lnkfile" - ? -  (File not found | COM-object registry key not found)
{42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" - "Microsoft Corporation" - C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{B327765E-D724-4347-8B16-78AE18552FC3} "NeroDigitalIconHandler Class" - "Nero AG" - C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll
{7F1CF152-04F8-453A-B34C-E609530A9DC8} "NeroDigitalPropSheetHandler Class" - "Nero AG" - C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll
{71A068F3-2DC9-438D-8944-6B4FF540D2F5} "QContextMenu Class" - "Quinnware" - C:\Program Files\Quintessential Media Player\QMPShell.dll
{71A466B0-65CC-4B41-9043-6090F2C830D3} "QIconHandler Class" - "Quinnware" - C:\Program Files\Quintessential Media Player\QMPShell.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? -  (File not found | COM-object registry key not found)
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\shlext.dll
{5E2121EE-0300-11D4-8D3B-444553540000} "SimpleShlExt Class" - ? - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? -  (File not found | COM-object registry key not found)

[Internet Explorer]
-----( HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser )-----
<binary data> "Google Toolbar" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
ITBar7Height "ITBar7Height" - ? -  (File not found | COM-object registry key not found)
<binary data> "ITBar7Layout" - ? -  (File not found | COM-object registry key not found)
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\ssv.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\ssv.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_29" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_29.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
{406B5949-7190-4245-91A9-30A17DE16AD0} "Snapfish Activia" - "Snapfish" - C:\Windows\Downloaded Program Files\SnapfishActivia1000.ocx / hxxp://www3.snapfish.de/SnapfishActivia.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBC} "ClsidExtension" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\ssv.dll
{53707962-6F74-2D53-2644-206D7942484F} "ClsidExtension" - "Safer Networking Limited" - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} "Recherchieren" - "Microsoft Corporation" - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
{898EA8C8-E7FF-479B-8935-AEC46303B9E5} "Skype Plug-In" - "Skype Technologies S.A." - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
AutorunsDisabled "AutorunsDisabled" - ? -  (File not found | COM-object registry key not found)
{AA58ED58-01DD-4d91-8333-CF10577473F7} "Google Toolbar Helper" - "Google Inc." - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "SSVHelper Class" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\ssv.dll

[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\christa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"ISUSPM Startup" - "Macrovision Corporation" - "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip  (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"avgnt" - "Avira GmbH" - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
"ISUSScheduler" - "Macrovision Corporation" - "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Microsoft Document Imaging Writer Monitor" - "Microsoft Corporation" - C:\Windows\system32\mdimon.dll
"PDFCreator" - ? - C:\Windows\system32\pdfcmnnt.dll  (File found, but it contains no detailed information)
"Toshiba Bluetooth Monitor" - "TOSHIBA CORPORATION." - C:\Windows\system32\tbtmon.dll

[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100" (WPFFontCache_v0400) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
"Avira AntiVir Guard" (AntiVirService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
"Avira AntiVir Planer" (AntiVirSchedulerService) - "Avira GmbH" - C:\Program Files\Avira\AntiVir Desktop\sched.exe
"Cyberlink RichVideo Service(CRVS)" (RichVideo) - ? - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
"DSL-Manager" (TDslMgrService) - "T-Systems Enterprise Services GmbH" - C:\Program Files\DSL-Manager\DslMgrSvc.exe
"Google Software Updater" (gusvc) - "Google" - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
"Google Update Service (gupdate)" (gupdate) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Google Update-Dienst (gupdatem)" (gupdatem) - "Google Inc." - C:\Program Files\Google\Update\GoogleUpdate.exe
"Microsoft .NET Framework NGEN v4.0.30319_X86" (clr_optimization_v4.0.30319_32) - "Microsoft Corporation" - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"O2Micro Flash Memory" (O2Flash) - "O2Micro International" - C:\Windows\system32\o2flash.exe
"Office Source Engine" (ose) - "Microsoft Corporation" - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
"SCM Driver Daemon" (NishService) - ? - C:\Program Files\System Control Manager\edd.exe  (File found, but it contains no detailed information)
"TOSHIBA Bluetooth Service" (TOSHIBA Bluetooth Service) - "TOSHIBA CORPORATION" - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

===[ Logfile end ]=========================================[ Logfile end ]===

If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru

Noch etwas!: Nach Neustart nach GMER Scan zeigte der Defender nach Einschalten eine kurze Nachricht, die ich mir so schnell nicht merken konnte (sinngemäß "irgendein Programm hat ... geändert"). Unter Verlauf fand ich dann:

Code:

Name          Warnstufe    Ausgeführte Aktion        Datum                  Status
unbekannt    unbekannt    zulassen                    09.01.2012 20:11      erfolgreich

Beschreibung:
Das Verhalten dieses Programms ist potenziell unerwünscht.

Empfehlung:
Lassen Sie dieses entdeckte Element nur zu, wenn Sie dem Programm oder dem Softwareherausgeber vertrauen.

Ressourcen:
regkey:
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ugloypob

file:
C:\Users\christa\AppData\Local\Temp\ugloypob.sys

Kategorie:
Noch nicht klassifiziert

Muss allerdings nicht mit der genannten Meldung zusammenhängen, denn gerade kam nach OSAM Scan und wiedereinschalten von Defender die gleiche Meldung: "ein bekanntes Prrogramm hat ... mpcmdrun.exe ..."

so, jetzt kommt der aswmbr dran. Bis später,

dieba

dieba 09.01.2012 22:34

aswmbr scan:

Code:

aswMBR version 0.9.9.1297 Copyright(c) 2011 AVAST Software
Run date: 2012-01-09 21:53:49
-----------------------------
21:53:49.646    OS Version: Windows 6.0.6002 Service Pack 2
21:53:49.646    Number of processors: 1 586 0x2402
21:53:49.646    ComputerName: FREIZEIT  UserName: christa
21:54:49.319    Initialize success
22:04:31.262    AVAST engine defs: 12010901
22:08:32.558    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
22:08:32.558    Disk 0 Vendor: TOSHIBA_MK1234GAX AC001A Size: 114473MB BusType: 3
22:08:32.590    Disk 0 MBR read successfully
22:08:32.605    Disk 0 MBR scan
22:08:32.949    Disk 0 unknown MBR code
22:08:32.980    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS      104006 MB offset 63
22:08:33.090    Disk 0 Partition 2 00    27 Hidden NTFS WinRE MSDOS5.0    10464 MB offset 213005835
22:08:33.152    Disk 0 scanning sectors +234436545
22:08:33.308    Disk 0 scanning C:\Windows\system32\drivers
22:09:04.074    Service scanning
22:09:06.199    Modules scanning
22:09:17.168    Disk 0 trace - called modules:
22:09:17.183    ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
22:09:17.183    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x849c25d8]
22:09:17.199    3 CLASSPNP.SYS[861a88b3] -> nt!IofCallDriver -> [0x83a83a10]
22:09:17.199    5 acpi.sys[806166bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x83648528]
22:09:18.855    AVAST engine scan C:\Windows
22:09:27.418    File: C:\Windows\PEV.exe  **INFECTED** Win32:Rootkit-gen [Rtk]
22:09:33.543    AVAST engine scan C:\Windows\system32
22:14:28.512    AVAST engine scan C:\Windows\system32\drivers
22:14:46.746    AVAST engine scan C:\Users\christa
22:18:44.481    File: C:\Users\christa\Downloads\route_anzeigen.exe  **INFECTED** Win32:Dropper-JQD [Drp]
22:25:34.341    AVAST engine scan C:\ProgramData
22:27:38.216    Scan finished successfully
22:30:19.716    Disk 0 MBR has been saved successfully to "C:\Users\christa\Desktop\MBR.dat"
22:30:19.716    The log file has been saved successfully to "C:\Users\christa\Desktop\aswMBR.txt"

Gruß, dieba

cosinus 09.01.2012 23:10

ugloypob ist von GMER, ein "random" Name:
Zitat:

Running: 3c5dcupk.exe; Driver: C:\Users\christa\AppData\Local\Temp\ugloypob.sys
Wir sollten den MBR fixen, sichere für den Fall der Fälle ALLE wichtigen Daten, auch wenn meistens alles glatt geht.

Hinweis: Mach bitte NICHT den MBR-Fix, wenn du noch andere Betriebssysteme wie zB Ubuntu installiert hast, ein MBR-Fix mit Windows-Tools macht ein parallel installiertes (Dualboot) Linux unbootbar.

Starte nach der Datensicherung aswmbr erneut und klick auf den Button FIXMBR.
Anschließend Windows neu starten und ein neues Log mit aswMBR machen.

dieba 10.01.2012 19:46

Hallo Arne,
sorry, gestern war es zu spät, komme jetzt erst dazu. Habe soweit alles gesichert (incl Backup vom 3.1., habe mit Belarc advisor noch alle Systemdaten, Software+license keys (extern) gespeichert. habe kein installiertes Ubuntu (nur live CD benutzt).
MBR-Fix mit aswMBR.exe? Runterladen der Virendefinition von avast dabei nicht notwendig?
Gruß, dieba

dieba 10.01.2012 20:45

sorry, mein Fehler, habe nochmal bei dir nachgelesen (aswmbr erneut starten) und Start von aswmbr zeigte, dass er natürlich die Virendefinitionen noch hat. Trotzdem noch eine Frage vor drücken des FIXMBR: am Netz bleiben und Defender und AV Guard aktiv lassen?
Gruß,dieba

cosinus 10.01.2012 21:33

Die Virenscanner am besten immer deaktivieren

dieba 10.01.2012 22:08

uff, fixMBR ist problemlos durchgelaufen, neustart auch! Der neue logfile scheint sich allerdings vom alten nicht zu unterscheiden?! (die beiden Infizierten Dateien werden noch angezeigt). FYI: ich habe übrigends bei den letzten scans die externe Festplatte nicht drangehabt.
aswMBR log:

Code:

aswMBR version 0.9.9.1297 Copyright(c) 2011 AVAST Software
Run date: 2012-01-10 21:47:43
-----------------------------
21:47:43.037    OS Version: Windows 6.0.6002 Service Pack 2
21:47:43.037    Number of processors: 1 586 0x2402
21:47:43.037    ComputerName: FREIZEIT  UserName: christa
21:48:20.053    Initialize success
21:48:32.490    AVAST engine defs: 12010901
21:48:48.006    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
21:48:48.022    Disk 0 Vendor: TOSHIBA_MK1234GAX AC001A Size: 114473MB BusType: 3
21:48:48.037    Disk 0 MBR read successfully
21:48:48.037    Disk 0 MBR scan
21:48:48.069    Disk 0 Windows VISTA default MBR code
21:48:48.069    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS      104006 MB offset 63
21:48:48.100    Disk 0 Partition 2 00    27 Hidden NTFS WinRE MSDOS5.0    10464 MB offset 213005835
21:48:48.115    Disk 0 scanning sectors +234436545
21:48:48.209    Disk 0 scanning C:\Windows\system32\drivers
21:49:03.694    Service scanning
21:49:05.600    Modules scanning
21:49:15.131    Disk 0 trace - called modules:
21:49:15.147    ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys dxgkrnl.sys atikmdag.sys
21:49:15.162    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84ac6ac8]
21:49:15.162    3 CLASSPNP.SYS[861a78b3] -> nt!IofCallDriver -> [0x83a83a10]
21:49:15.178    5 acpi.sys[806146bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x83648528]
21:49:18.209    AVAST engine scan C:\Windows
21:49:23.006    File: C:\Windows\PEV.exe  **INFECTED** Win32:Rootkit-gen [Rtk]
21:49:30.959    AVAST engine scan C:\Windows\system32
21:52:57.287    AVAST engine scan C:\Windows\system32\drivers
21:53:12.756    AVAST engine scan C:\Users\christa
21:55:34.803    File: C:\Users\christa\Downloads\route_anzeigen.exe  **INFECTED** Win32:Dropper-JQD [Drp]
21:59:20.865    AVAST engine scan C:\ProgramData
22:01:19.147    Scan finished successfully
22:01:48.459    Disk 0 MBR has been saved successfully to "C:\Users\christa\Desktop\MBR.dat"
22:01:48.475    The log file has been saved successfully to "C:\Users\christa\Desktop\aswMBR2.txt"


cosinus 10.01.2012 22:22

Der UNterschied ist hier:
Code:

Disk 0 Windows VISTA default MBR code
Und so soll es auch sein.

Code:

File: C:\Windows\PEV.exe  **INFECTED** Win32:Rootkit-gen [Rtk]
Das ist ein Fehlalarm.Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs.
Denk dran beide Tools zu updaten vor dem Scan!!


Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


dieba 11.01.2012 09:16

Hallo Arne,
Malwarebytes hatte nichts gefunden (hatte allerdings auch nicht die externe Festplatte dran, werde es nachholen). Superantispyware hatte jede Menge cookies und 2 Funde auf der externen Platte, habe sie in Quarantäne geschickt. Interessanterweise waren die "Trojan.Agent/Gen-FraudPack" in der "Marco Polo Euroroute 2007" Software, die mit dem (2007 bei Lidl) gekauften Rechner installiert mitgeliefert wurde. Auf der c-Platte wurde der Trojaner vermutlich nicht mehr gefunden, da ich die Software als nie/kaum? benutzt nach dem backup deinstalliert hatte.

Code:

Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Datenbank Version: v2012.01.10.06

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
christa :: FREIZEIT [Administrator]

10.01.2012 22:32:05
mbam-log-2012-01-10 (22-32-05).txt

Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 288705
Laufzeit: 1 Stunde(n), 23 Minute(n), 9 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)

und
Code:

SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com

Generated 01/11/2012 at 05:16 AM

Application Version : 5.0.1142

Core Rules Database Version : 8120
Trace Rules Database Version: 5932

Scan type      : Complete Scan
Total Scan Time : 04:57:46

Operating System Information
Windows Vista Home Basic 32-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Administrator

Memory items scanned      : 567
Memory threats detected  : 0
Registry items scanned    : 37862
Registry threats detected : 0
File items scanned        : 292332
File threats detected    : 354

Adware.Tracking Cookie
        C:\Users\christa\AppData\Roaming\Microsoft\Windows\Cookies\christa@adx.chip[1].txt [ /adx.chip ]
        C:\Users\christa\AppData\Roaming\Microsoft\Windows\Cookies\christa@bs.serving-sys[1].txt [ /bs.serving-sys ]
        C:\Users\christa\AppData\Roaming\Microsoft\Windows\Cookies\christa@casalemedia[1].txt [ /casalemedia ]
        C:\Users\christa\AppData\Roaming\Microsoft\Windows\Cookies\christa@doubleclick[2].txt [ /doubleclick ]
        C:\Users\christa\AppData\Roaming\Microsoft\Windows\Cookies\christa@questionmarket[2].txt [ /questionmarket ]
        C:\Users\christa\AppData\Roaming\Microsoft\Windows\Cookies\christa@serving-sys[2].txt [ /serving-sys ]
        C:\Users\christa\AppData\Roaming\Microsoft\Windows\Cookies\christa@smartadserver[1].txt [ /smartadserver ]
        C:\Users\christa\AppData\Roaming\Microsoft\Windows\Cookies\christa@snapfish.112.2o7[1].txt [ /snapfish.112.2o7 ]
        C:\Users\christa\AppData\Roaming\Microsoft\Windows\Cookies\christa@statse.webtrendslive[2].txt [ /statse.webtrendslive ]
        C:\Users\christa\AppData\Roaming\Microsoft\Windows\Cookies\christa@tracking.quisma[2].txt [ /tracking.quisma ]
        C:\Users\christa\AppData\Roaming\Microsoft\Windows\Cookies\christa@tradedoubler[2].txt [ /tradedoubler ]
        C:\Users\christa\AppData\Roaming\Microsoft\Windows\Cookies\christa@xiti[1].txt [ /xiti ]
        C:\Users\christa\AppData\Roaming\Microsoft\Windows\Cookies\christa@zanox[1].txt [ /zanox ]
        C:\Users\christa\AppData\Roaming\Microsoft\Windows\Cookies\NHXXT8DC.txt [ /atdmt.com ]
        C:\USERS\CHRISTA\AppData\Roaming\Microsoft\Windows\Cookies\Low\christa@advertising[1].txt [ Cookie:christa@advertising.com/ ]
        C:\USERS\CHRISTA\AppData\Roaming\Microsoft\Windows\Cookies\Low\christa@2o7[1].txt [ Cookie:christa@2o7.net/ ]
        C:\USERS\CHRISTA\AppData\Roaming\Microsoft\Windows\Cookies\Low\christa@mediaplex[1].txt [ Cookie:christa@mediaplex.com/ ]
        C:\USERS\CHRISTA\AppData\Roaming\Microsoft\Windows\Cookies\Low\christa@doubleclick[1].txt [ Cookie:christa@doubleclick.net/ ]
        C:\USERS\CHRISTA\Cookies\christa@smartadserver[1].txt [ Cookie:christa@smartadserver.com/ ]
        C:\USERS\CHRISTA\Cookies\christa@adx.chip[1].txt [ Cookie:christa@adx.chip.de/ ]
        C:\USERS\CHRISTA\Cookies\christa@bs.serving-sys[1].txt [ Cookie:christa@bs.serving-sys.com/ ]
        C:\USERS\CHRISTA\Cookies\christa@statse.webtrendslive[2].txt [ Cookie:christa@statse.webtrendslive.com/ ]
        C:\USERS\CHRISTA\Cookies\christa@zanox[1].txt [ Cookie:christa@zanox.com/ ]
        C:\USERS\CHRISTA\Cookies\christa@serving-sys[2].txt [ Cookie:christa@serving-sys.com/ ]
        C:\USERS\CHRISTA\Cookies\NHXXT8DC.txt [ Cookie:christa@atdmt.com/ ]
        C:\USERS\CHRISTA\Cookies\christa@tradedoubler[2].txt [ Cookie:christa@tradedoubler.com/ ]
        C:\USERS\CHRISTA\Cookies\christa@casalemedia[1].txt [ Cookie:christa@casalemedia.com/ ]
        C:\USERS\CHRISTA\Cookies\christa@tracking.quisma[2].txt [ Cookie:christa@tracking.quisma.com/ ]
        C:\USERS\CHRISTA\Cookies\christa@snapfish.112.2o7[1].txt [ Cookie:christa@snapfish.112.2o7.net/ ]
        C:\USERS\CHRISTA\Cookies\christa@doubleclick[2].txt [ Cookie:christa@doubleclick.net/ ]
        ia.media-imdb.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\ETTH7J73 ]
        media.kyte.tv [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\ETTH7J73 ]
        media.scanscout.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\ETTH7J73 ]
        media01.kyte.tv [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\ETTH7J73 ]
        media10.washingtonpost.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\ETTH7J73 ]
        www.crossmedia2.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\ETTH7J73 ]
        www.digital-media-repository.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\ETTH7J73 ]
        www.pornhub.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\ETTH7J73 ]
        E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\CHRISTA@ADX.CHIP[1].TXT [ /ADX.CHIP ]
        E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\CHRISTA@BS.SERVING-SYS[1].TXT [ /BS.SERVING-SYS ]
        E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\CHRISTA@CASALEMEDIA[1].TXT [ /CASALEMEDIA ]
        E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\CHRISTA@DOUBLECLICK[2].TXT [ /DOUBLECLICK ]
        E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\CHRISTA@QUESTIONMARKET[2].TXT [ /QUESTIONMARKET ]
        E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\CHRISTA@SERVING-SYS[2].TXT [ /SERVING-SYS ]
        E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\CHRISTA@SMARTADSERVER[1].TXT [ /SMARTADSERVER ]
        E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\CHRISTA@SNAPFISH.112.2O7[1].TXT [ /SNAPFISH.112.2O7 ]
        E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\CHRISTA@STATSE.WEBTRENDSLIVE[2].TXT [ /STATSE.WEBTRENDSLIVE ]
        E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\CHRISTA@TRACKING.QUISMA[2].TXT [ /TRACKING.QUISMA ]
        E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\CHRISTA@TRADEDOUBLER[2].TXT [ /TRADEDOUBLER ]
        E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\CHRISTA@XITI[1].TXT [ /XITI ]
        E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\CHRISTA@ZANOX[1].TXT [ /ZANOX ]
        E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\CHRISTA@2O7[1].TXT [ /2O7 ]
        E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\CHRISTA@ADVERTISING[1].TXT [ /ADVERTISING ]
        E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\CHRISTA@DOUBLECLICK[1].TXT [ /DOUBLECLICK ]
        E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\CHRISTA@MEDIAPLEX[1].TXT [ /MEDIAPLEX ]
        E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\CHRISTA@MSNPORTAL.112.2O7[1].TXT [ /MSNPORTAL.112.2O7 ]
        in.getclicky.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        tracking.klicktel.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        stats.amrum.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        stats.amrum.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.bluecounter.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        count.primawebtools.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        tracking.oe24.at [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        tracking.oe24.at [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        stat.www.fi [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        stats.realconsulter.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .gemoneysdenac.112.2o7.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        wke.wikimedia.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        wke.wikimedia.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        wke.wikimedia.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .tescostores.122.2o7.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .pelmorexmedia.122.2o7.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        api.firestormmedia.tv [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .phazeporn.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        s06.flagcounter.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .heavenwarez.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .heavenwarez.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .heavenwarez.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .heavenwarez.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .heavenwarez.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .heavenwarez.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .gostats.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .gostats.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        s03.flagcounter.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .gostats.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .toplist.cz [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .photosex.biz [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .photosex.biz [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .photosex.biz [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .web-stat.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .web-stat.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .web-stat.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .wissende.122.2o7.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .xnetporn.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .gostats.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .gostats.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .gostats.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .toplist.sk [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.pornlove.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.pornlove.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.pornlove.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .pornlove.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.pornlove.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.pornlove.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.pornlove.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.pornlove.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.pornlove.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .pornlove.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .pornlove.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .xnetporn.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .xnetporn.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        wareztown.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        wareztown.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .wareztown.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .wareztown.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .wareztown.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .wareztown.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .phazeporn.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .phazeporn.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .seaporn.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.seaporn.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .seaporn.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .seaporn.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.instawarez.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.instawarez.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .instawarez.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .instawarez.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .instawarez.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .pornhub.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .pornhub.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .pornhub.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .pornhub.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .pornhub.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        005.free-counters.co.uk [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .guj.122.2o7.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        track.adform.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .zieltrack.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        6.zieltrack.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        167.zieltrack.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        nl.sitestat.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        nl.sitestat.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .droetker.122.2o7.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        stat.aldi.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.flf-counter.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .atracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .gemoneysdecapital.112.2o7.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        s04.flagcounter.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        tracking.mixxt.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.bluecounter.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        go.dynamic-tracking.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        wstat.wibiya.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .microsoftsto.112.2o7.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .gostats.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .reunioncom.112.2o7.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .snapfish.112.2o7.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        sales.liveperson.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        livestat.derstandard.at [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        stats.amrum.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.flf-counter.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        tracking.klicktel.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        track.webtrekk.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        blog.wikimedia.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        blog.wikimedia.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        meta.wikimedia.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .shinystat.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        commons.wikimedia.org [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ E:\CHRISTA\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        C:\USERS\CHRISTA\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\CHRISTA@MSNPORTAL.112.2O7[1].TXT [ /MSNPORTAL.112.2O7 ]
        in.getclicky.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .xiti.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        tracking.klicktel.de [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        stats.amrum.de [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        stats.amrum.de [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        tracking.oe24.at [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        stat.www.fi [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        stats.realconsulter.de [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .webmasterplan.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .gemoneysdenac.112.2o7.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        wke.wikimedia.de [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .tescostores.122.2o7.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .pelmorexmedia.122.2o7.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        api.firestormmedia.tv [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .heavenwarez.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .heavenwarez.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .heavenwarez.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .heavenwarez.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .gostats.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .yadro.ru [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .photosex.biz [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .web-stat.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .web-stat.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .web-stat.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .imrworldwide.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .wissende.122.2o7.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.pornlove.org [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.pornlove.org [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.pornlove.org [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.pornlove.org [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.pornlove.org [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.pornlove.org [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.pornlove.org [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.pornlove.org [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .pornlove.org [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .xnetporn.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        wareztown.org [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        wareztown.org [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .wareztown.org [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .wareztown.org [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .phazeporn.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .seaporn.org [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.instawarez.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.instawarez.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .instawarez.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .pornhub.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        005.free-counters.co.uk [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .invitemedia.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .doubleclick.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .guj.122.2o7.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .adfarm1.adition.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .zieltrack.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        ad.zanox.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        nl.sitestat.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        nl.sitestat.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .droetker.122.2o7.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        stat.aldi.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .gemoneysdecapital.112.2o7.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        de.sitestat.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        s04.flagcounter.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        tracking.mixxt.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .histats.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        wstat.wibiya.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .microsoftsto.112.2o7.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .reunioncom.112.2o7.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .snapfish.112.2o7.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .liveperson.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        livestat.derstandard.at [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        stats.amrum.de [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .statcounter.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        tracking.klicktel.de [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        track.webtrekk.de [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        blog.wikimedia.de [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        meta.wikimedia.org [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .shinystat.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .tracking.quisma.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        statse.webtrendslive.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        commons.wikimedia.org [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .2o7.net [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        tracking.quisma.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        www.etracker.de [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .clickandbuy.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .accounts.google.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        accounts.youtube.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        accounts.google.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .getclicky.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        .static.getclicky.com [ C:\USERS\CHRISTA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8P6T23GQ.DEFAULT\COOKIES.SQLITE ]
        C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\SYSTEM@XITI[1].TXT [ /XITI ]

Trojan.Agent/Gen-FraudPack
        ZIP ARCHIVE( E:\FREIZEIT\BACKUP SET 2012-01-03 205310\BACKUP FILES 2012-01-03 205310\BACKUP FILES 20.ZIP )/C\PROGRAM FILES\MARCO POLO EUROROUTE 2007\PROG\DXBAREXTITEMSD9.BPL
        E:\FREIZEIT\BACKUP SET 2012-01-03 205310\BACKUP FILES 2012-01-03 205310\BACKUP FILES 20.ZIP

Gruß, dieba

cosinus 11.01.2012 11:50

Nur cookies und zwei Fehlalarme. Was ist mit ESET?

dieba 11.01.2012 11:59

bin gerade zurückgekommen und setze ihn sofort auf. mit externer platte? (dauert ziemlich länger)

cosinus 11.01.2012 12:18

Ja mach mit ext. Platte

dieba 11.01.2012 16:15

... nur unsere beiden alten Bekannten:

Code:

ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=6266d81321a59146a8a86d684cc241d9
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-07 06:32:18
# local_time=2012-01-07 07:32:18 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 130312821 130312821 0 0
# compatibility_mode=1797 16775165 100 100 619206 100845182 102964 0
# compatibility_mode=5892 16776574 100 100 4839 163481390 0 0
# compatibility_mode=8192 67108863 100 0 20823 20823 0 0
# scanned=186046
# found=2
# cleaned=0
# scan_time=12519
C:\Users\christa\Downloads\route_anzeigen.exe        a variant of Win32/Foxferi.A trojan (unable to clean)        00000000000000000000000000000000        I
E:\Christa\Users\christa\Downloads\route_anzeigen.exe        a variant of Win32/Foxferi.A trojan (unable to clean)        00000000000000000000000000000000        I
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=6266d81321a59146a8a86d684cc241d9
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2012-01-11 02:54:25
# local_time=2012-01-11 03:54:25 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 130645950 130645950 0 0
# compatibility_mode=1797 16775165 100 100 5838 101178311 0 0
# compatibility_mode=5892 16776574 100 100 4053 163814519 0 0
# compatibility_mode=8192 67108863 100 0 353952 353952 0 0
# scanned=177070
# found=2
# cleaned=0
# scan_time=11918
C:\Users\christa\Downloads\route_anzeigen.exe        a variant of Win32/Foxferi.A trojan (unable to clean)        00000000000000000000000000000000        I
E:\Christa\Users\christa\Downloads\route_anzeigen.exe        a variant of Win32/Foxferi.A trojan (unable to clean)        00000000000000000000000000000000        I

Gruß, dieba

cosinus 11.01.2012 17:26

Zitat:

C:\Users\christa\Downloads\route_anzeigen.exe
E:\Christa\Users\christa\Downloads\route_anzeigen.exe
Solltest du das nicht schon längst gelöscht haben? :confused:

dieba 11.01.2012 18:39

hätte ich schon längst, aber:

Zitat:

Gehe sicher das bei Remove Found Threats kein Haken gesetzt ist.
und du hattest es mE nicht explizit gesagt. Sind jetzt aber gelöscht!

Gruß, dieba

cosinus 11.01.2012 18:42

Es geht ja auch um die Präsentation der Ergebnisse, die Funde sollen nicht OHNE vorherige Sichtung einfach so gelöscht werden!
Dann hab ich die Datei ausgewertet und wir haben festgestellt dass es ein Schädling ist => Prüfung/Sichtung erfolgt, dann weg damit

dieba 11.01.2012 18:47

ok. Dann soweit alles klar? Werde demnächst noch ein paar überflüssige Sachen deinstallieren. Macht ccleaner danach Sinn?

Gruß, dieba

cosinus 11.01.2012 19:59

Ja CCleaner kann man machen aber Finger weg von der Registry.
Rechner soweit wieder ok?

dieba 11.01.2012 21:08

Hallo Arne,
soweit ich es in der Kürze beurteilen kann, käuft er ok. Das Einzige, was mir bisher aufgefallen ist: der pdfmaker tut es nicht mehr, erzeugt zwar eine temp. ps-datei, aber keine PDF-datei. Hatte ihn noch am 2.1. benutzt, da lief er noch. Vielleicht hilft Neuinstallation. Ach ja und wie sieht es mit "Aufräumen" aus, was behalten, was deinstallieren?

Wenn es das war, dann ist es Zeit, mich ganz herzlich zu bedanken. Ich finde, ihr macht einen tollen Job, den man vor allem dann zu würdigen weiss, wenn man sich hilfesuchend an euch wendet!

Werde jetzt mal in Ruhe eure "Maßnahmen zur Absicherung des Rechners" durcharbeiten, Software aufräumen etc. Spybot sollte ich wohl nicht mehr verwenden, hatte schon gemerkt, dass er die hostsdatei aufbläht.
Sollte mir noch etwas "spanisch" vorkommen oder nicht richtig funktionieren, kann ich das dann noch hier posten?
Sorry, noch ´ne letzte Frage: superfetch wieder aktivieren?

Liebe Grüße und nochmals :dankeschoen:,
dieba

cosinus 11.01.2012 21:15

Alternative zu pdfmaker (oder meinst du pdfcrator) => Ghostscript + FreePDF => FreePDFXP.de
Superfetch kannst aktivieren

Dann wären wir durch! :abklatsch:

Die Programme, die hier zum Einsatz kamen, können alle wieder runter. CF kann über Start, Ausführen mit combofix /uninstall entfernt werden. Melde dich falls es da Fehlermeldungen zu gibt.
Malwarebytes zu behalten ist kein Fehler. Kannst ja 1x im Monat damit scannen, aber immer vorher ans Update denken.

Bitte abschließend die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate

Windows XP: Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.

Windows Vista/7: Anleitung Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:

Adobe - Andere Version des Adobe Flash Player installieren

Notfalls kann man auch von Chip.de runterladen => http://filepony.de/?q=Flash+Player

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein Sicherheitsrisiko, daher solltest Du die alten Versionen löschen (falls vorhanden, am besten mit JavaRa) und auf die neuste aktualisieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.

dieba 11.01.2012 21:29

Danke für die weiteren Hinweise. Ich meinte natürlich pdfcreator.
Noch ein Hinweis zu Java: hatte auf meinem Rechner (Win 7) vor kurzem Java 7 installiert und alle alten deinstalliert, worauf mich prompt bei der nächsten Gelegenheit firefox (neueste Version) anmeckerte, dass ihm das java 6 plugin fehlte und ich es nachinstallieren musste. Ne Ahnung warum? Naja , wenn ich mich von der Strapaze etwas erholt habe, werde ich mir mal meinen Rechner genauer unter die Lupe nehmen. Hoffentlich muss ich dann nicht wieder auf eure Hilfe zurückgreifen.

Alles Gute und viel Erfolg weiterhin,
dieba

cosinus 11.01.2012 21:46

Manchmal hakt es noch mit Java7.
Notfalls Java7 deinstallieren und das aktuellste Java6 installieren.

dieba 12.01.2012 00:41

Nachtrag: ich hatte Java 7 64bit-Version installiert, firefox 32bit - daher!

cosinus 12.01.2012 19:13

Hm, guter Einwand, vllt sollte ich mal erwähnen, dass man die 32- und 64-Bit-Version installieren muss, wenn man ein 64-Bit Windows hat.


Alle Zeitangaben in WEZ +1. Es ist jetzt 06:31 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130